SlideShare a Scribd company logo
Security and
governance
done right
Prof. Hernan Huwyler, MBA CPA
Agenda
Centralize risk-based controls
SAP GRC to simplify compliance
Streamline access certifications
Monitor with red flags analytics
Manage segregation of duties rulesets
The centralization of
processes is a
prerequisite for cost
saving and digitalization
efforts in response to the
COVID19 crisis
GRPC_STR_CHANGE
Update and simplify the
hierarchy of SAP processes
and sub-processes
GRPCRTA_PC
Centralize local
control catalogs with
harmonized multi-
compliance
frameworks
ASGN-TSTER
Change the schedule
of controls with
problematic
workflows
SURVEY
Align control surveys to
yes/no confirmations with
comments and attachments
The detection and
investigation of
suspicious fraudulent
activity is critical
during the operational
adjustments triggered by
COVID19
The economic crisis
requires to closely
monitor partners for
performance, solvency and
service continuity risks
SAP Business Partner
Screening
Ongoing due diligence on
third-parties
SAP Business Integrity
Screening
Notifications on fraud red
flags
SAP Tax Compliance
Prevent fines and disputes
SAP Risk Management
Develop exit plans to
address continuiry risks
SAP Risk Management
Monte Carlo Simulations
• cash-flow analysis
• delays in supply
• delays in orders
• budgeting
• insurance
• price calculation
• bidding
• Update process owners
• Compare changes in the most
used roles
User access reviews
• Evaluate recent changes for
terminations and contractors
• Sample some reviews to
audit the full process
The operational changes
during COVID19 triggered
numerous inconsistencies
in SAP data for cleanup
SAP Business Integrity
Screening
Exception reporting and
management
• Duplicated payments
• Split orders
• Invoice before reception
• Inaccurate master data
• Unusual discounts
SAP
Segregation of
duties
Ruleset
• Review changes in the
access control attributes
• Leverage checks based
on pre-configured SAP
Best Practices for
industry
• Continue improving the
rules for display rights
• Simplify roles for the new
normal
Let´s connect
Prof. Hernan Huwyler
/in/hernanwyler/
hewyler
Leading analysts on information
security in the era of digital
transformation
@kuppingercole
info@kuppingercole.com

More Related Content

What's hot

Let me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this yearLet me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this year
Hernan Huwyler, MBA CPA
 
Managing Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus CrisisManaging Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus Crisis
Hernan Huwyler, MBA CPA
 
Qa Financials - 10 Smart Controls for Software Development
Qa Financials  - 10 Smart Controls for Software DevelopmentQa Financials  - 10 Smart Controls for Software Development
Qa Financials - 10 Smart Controls for Software Development
Hernan Huwyler, MBA CPA
 
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler, MBA CPA
 
Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks
Hernan Huwyler, MBA CPA
 
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
Hernan Huwyler, MBA CPA
 
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance RisksHernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler, MBA CPA
 
Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler, MBA CPA
 
AReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature EnoughAReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature Enough
Hernan Huwyler, MBA CPA
 
Altran Financial Services
Altran Financial ServicesAltran Financial Services
Altran Financial Services
ianthm
 
ClockworkISMS
ClockworkISMSClockworkISMS
ClockworkISMS
Delaney
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard Jim Robins
 
Effective Security Metrics
Effective Security MetricsEffective Security Metrics
Effective Security Metrics
InnoTech
 
Supplier Management- HICX Solutions
Supplier Management- HICX SolutionsSupplier Management- HICX Solutions
Supplier Management- HICX Solutions
Rohini Sharma
 
Implementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan HuwylerImplementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan Huwyler
Hernan Huwyler, MBA CPA
 
RISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — DoesRISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — Does
TechPoint
 
Thematic compliance
Thematic complianceThematic compliance
SafePaaS AuditPaaS
SafePaaS AuditPaaS SafePaaS AuditPaaS
SafePaaS AuditPaaS
Jane Jones
 

What's hot (20)

Let me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this yearLet me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this year
 
Managing Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus CrisisManaging Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus Crisis
 
Qa Financials - 10 Smart Controls for Software Development
Qa Financials  - 10 Smart Controls for Software DevelopmentQa Financials  - 10 Smart Controls for Software Development
Qa Financials - 10 Smart Controls for Software Development
 
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized World
 
Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks
 
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
 
RAP GC 2016
RAP GC 2016RAP GC 2016
RAP GC 2016
 
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance RisksHernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
 
Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340
 
AReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature EnoughAReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature Enough
 
Altran Financial Services
Altran Financial ServicesAltran Financial Services
Altran Financial Services
 
ClockworkISMS
ClockworkISMSClockworkISMS
ClockworkISMS
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard
 
Effective Security Metrics
Effective Security MetricsEffective Security Metrics
Effective Security Metrics
 
Supplier Management- HICX Solutions
Supplier Management- HICX SolutionsSupplier Management- HICX Solutions
Supplier Management- HICX Solutions
 
Implementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan HuwylerImplementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan Huwyler
 
RISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — DoesRISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — Does
 
GP for Risk Management product sheet
GP for Risk Management product sheetGP for Risk Management product sheet
GP for Risk Management product sheet
 
Thematic compliance
Thematic complianceThematic compliance
Thematic compliance
 
SafePaaS AuditPaaS
SafePaaS AuditPaaS SafePaaS AuditPaaS
SafePaaS AuditPaaS
 

Similar to Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA

Operational Transformation in Banking Operations
Operational Transformation in Banking OperationsOperational Transformation in Banking Operations
Operational Transformation in Banking OperationsRajeev De Roy
 
GRC
GRCGRC
ERP for Manufacturing Industry
ERP for Manufacturing IndustryERP for Manufacturing Industry
ERP for Manufacturing Industryvelcomerp
 
Telecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc eraTelecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc era
Ehtisham Rao
 
Delivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and LogisticsDelivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and Logistics
SAP Technology
 
Evaluating and improving business process
Evaluating and improving business processEvaluating and improving business process
Evaluating and improving business processdutconsult
 
GRC: Identify and reduce business risks
GRC: Identify and reduce business risksGRC: Identify and reduce business risks
GRC: Identify and reduce business risks
write2kanika
 
Money Saving
Money SavingMoney Saving
Managed Services Using SLAs and KPIs
Managed Services Using SLAs and KPIsManaged Services Using SLAs and KPIs
Managed Services Using SLAs and KPIs
Prolifics
 
Propeotech solution
Propeotech solutionPropeotech solution
Propeotech solutionbhuppi
 
Multi Vendor Management
Multi Vendor ManagementMulti Vendor Management
Multi Vendor Management
MuratSelcuk
 
Accenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A ServiceAccenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A Service
accenture
 
Managing Today’s Supply Chain
Managing Today’s Supply ChainManaging Today’s Supply Chain
Managing Today’s Supply Chain
mubarak2009
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Hernan Huwyler, MBA CPA
 
How To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global DeploymentHow To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global Deploymentdreamforce2006
 
Cloudway sipm capabilities
Cloudway sipm capabilitiesCloudway sipm capabilities
Cloudway sipm capabilities
Saumya S
 
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
SAP Customer Experience
 
Automating Key Accountancy Processes
Automating Key Accountancy ProcessesAutomating Key Accountancy Processes
Automating Key Accountancy Processes
BlackLine
 
Delivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for TelecommunicationDelivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for Telecommunication
SAP Technology
 
Quality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance MeasurementQuality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance Measurement
mubarak2009
 

Similar to Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA (20)

Operational Transformation in Banking Operations
Operational Transformation in Banking OperationsOperational Transformation in Banking Operations
Operational Transformation in Banking Operations
 
GRC
GRCGRC
GRC
 
ERP for Manufacturing Industry
ERP for Manufacturing IndustryERP for Manufacturing Industry
ERP for Manufacturing Industry
 
Telecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc eraTelecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc era
 
Delivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and LogisticsDelivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and Logistics
 
Evaluating and improving business process
Evaluating and improving business processEvaluating and improving business process
Evaluating and improving business process
 
GRC: Identify and reduce business risks
GRC: Identify and reduce business risksGRC: Identify and reduce business risks
GRC: Identify and reduce business risks
 
Money Saving
Money SavingMoney Saving
Money Saving
 
Managed Services Using SLAs and KPIs
Managed Services Using SLAs and KPIsManaged Services Using SLAs and KPIs
Managed Services Using SLAs and KPIs
 
Propeotech solution
Propeotech solutionPropeotech solution
Propeotech solution
 
Multi Vendor Management
Multi Vendor ManagementMulti Vendor Management
Multi Vendor Management
 
Accenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A ServiceAccenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A Service
 
Managing Today’s Supply Chain
Managing Today’s Supply ChainManaging Today’s Supply Chain
Managing Today’s Supply Chain
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
 
How To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global DeploymentHow To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global Deployment
 
Cloudway sipm capabilities
Cloudway sipm capabilitiesCloudway sipm capabilities
Cloudway sipm capabilities
 
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
 
Automating Key Accountancy Processes
Automating Key Accountancy ProcessesAutomating Key Accountancy Processes
Automating Key Accountancy Processes
 
Delivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for TelecommunicationDelivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for Telecommunication
 
Quality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance MeasurementQuality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance Measurement
 

More from Hernan Huwyler, MBA CPA

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Hernan Huwyler, MBA CPA
 
Model to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdfModel to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdf
Hernan Huwyler, MBA CPA
 
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsProf Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Hernan Huwyler, MBA CPA
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Hernan Huwyler, MBA CPA
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler, MBA CPA
 
The Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfThe Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdf
Hernan Huwyler, MBA CPA
 
R is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using RR is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using R
Hernan Huwyler, MBA CPA
 
Compliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerCompliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan Huwyler
Hernan Huwyler, MBA CPA
 
DPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksDPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy Risks
Hernan Huwyler, MBA CPA
 
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerMaster in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Hernan Huwyler, MBA CPA
 
Cyber Laundering and the AML Directives
Cyber Laundering and the AML DirectivesCyber Laundering and the AML Directives
Cyber Laundering and the AML Directives
Hernan Huwyler, MBA CPA
 
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler, MBA CPA
 
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
Hernan Huwyler, MBA CPA
 
10 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 3730110 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 37301
Hernan Huwyler, MBA CPA
 
Information Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksInformation Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT Risks
Hernan Huwyler, MBA CPA
 
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
Hernan Huwyler, MBA CPA
 
IDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk dataIDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk data
Hernan Huwyler, MBA CPA
 
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimientoUCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
Hernan Huwyler, MBA CPA
 
Master Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan HuwylerMaster Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan Huwyler
Hernan Huwyler, MBA CPA
 
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapProf- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Hernan Huwyler, MBA CPA
 

More from Hernan Huwyler, MBA CPA (20)

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
 
Model to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdfModel to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdf
 
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsProf Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
 
The Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfThe Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdf
 
R is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using RR is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using R
 
Compliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerCompliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan Huwyler
 
DPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksDPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy Risks
 
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerMaster in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
 
Cyber Laundering and the AML Directives
Cyber Laundering and the AML DirectivesCyber Laundering and the AML Directives
Cyber Laundering and the AML Directives
 
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
 
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
 
10 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 3730110 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 37301
 
Information Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksInformation Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT Risks
 
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
 
IDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk dataIDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk data
 
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimientoUCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
 
Master Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan HuwylerMaster Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan Huwyler
 
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapProf- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
 

Recently uploaded

falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
Falcon Invoice Discounting
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
ofm712785
 
VAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and RequirementsVAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and Requirements
uae taxgpt
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
HARSHITHV26
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
Bojamma2
 
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Lviv Startup Club
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
Operational Excellence Consulting
 
Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143
Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143
Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143
bosssp10
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
Workforce Group
 
What is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdfWhat is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdf
seoforlegalpillers
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
dylandmeas
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
Ben Wann
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
zoyaansari11365
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
Ben Wann
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
dylandmeas
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
Adam Smith
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
KaiNexus
 
LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024
Lital Barkan
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
awaisafdar
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
SynapseIndia
 

Recently uploaded (20)

falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
 
VAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and RequirementsVAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and Requirements
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
 
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
Evgen Osmak: Methods of key project parameters estimation: from the shaman-in...
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
 
Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143
Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143
Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta 143
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
 
What is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdfWhat is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdf
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
 
LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 

Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA

  • 2. Agenda Centralize risk-based controls SAP GRC to simplify compliance Streamline access certifications Monitor with red flags analytics Manage segregation of duties rulesets
  • 3. The centralization of processes is a prerequisite for cost saving and digitalization efforts in response to the COVID19 crisis
  • 4. GRPC_STR_CHANGE Update and simplify the hierarchy of SAP processes and sub-processes GRPCRTA_PC Centralize local control catalogs with harmonized multi- compliance frameworks ASGN-TSTER Change the schedule of controls with problematic workflows SURVEY Align control surveys to yes/no confirmations with comments and attachments
  • 5. The detection and investigation of suspicious fraudulent activity is critical during the operational adjustments triggered by COVID19
  • 6. The economic crisis requires to closely monitor partners for performance, solvency and service continuity risks
  • 7. SAP Business Partner Screening Ongoing due diligence on third-parties SAP Business Integrity Screening Notifications on fraud red flags SAP Tax Compliance Prevent fines and disputes SAP Risk Management Develop exit plans to address continuiry risks
  • 8. SAP Risk Management Monte Carlo Simulations • cash-flow analysis • delays in supply • delays in orders • budgeting • insurance • price calculation • bidding
  • 9. • Update process owners • Compare changes in the most used roles User access reviews • Evaluate recent changes for terminations and contractors • Sample some reviews to audit the full process
  • 10. The operational changes during COVID19 triggered numerous inconsistencies in SAP data for cleanup
  • 11. SAP Business Integrity Screening Exception reporting and management • Duplicated payments • Split orders • Invoice before reception • Inaccurate master data • Unusual discounts
  • 12. SAP Segregation of duties Ruleset • Review changes in the access control attributes • Leverage checks based on pre-configured SAP Best Practices for industry • Continue improving the rules for display rights • Simplify roles for the new normal
  • 13. Let´s connect Prof. Hernan Huwyler /in/hernanwyler/ hewyler
  • 14. Leading analysts on information security in the era of digital transformation @kuppingercole info@kuppingercole.com

Editor's Notes

  1. security and governance done right - How to centralize risk-based controls in SAP GRC to simplify compliance - Tips to streamline access certifications and monitoring with red flags analytics - How to manage segregation of duties rulesets
  2. Hierarchy GRPC_STR_DISPLAY: Use the needs for reports following the C-level organization and the hierarchy of regulations, cannot centralize inconsistent processes, review with process owners the relevance, reassess the process to focus the resources Centralization: many control frameworks, follow group policies, assess the justification of having differetent controls in some entities, centralize the delegation of tasks for other users´ access rights. SAP and non-SAP applications. Use generic test plans for control clusters corporate, financial, IT, and industry-specific Schedule: evaluate the frequency to test controls, test shared controls by shared service centers, look for recurrent escalation of issues or rejected or pending.
  3. SAP GRC to simplify compliance: fraud, more risks from work from home How can we reduce risks from business partners, business integrity of partners Standard risk management should be done better (e.g- Credit Swiss dismissing the CRO)7 Need for a real management of risks, update and audit action plans, prevent hiding risks
  4. Scenario analysis using Monte Carlo enables you to select a list of risks, assign them to a random distribution, and decide on a distribution method for the number of losses involved (frequency). In this way, the system estimates the total aggregated loss (the sum) at risk for your simulation.
  5. Detect changes in uses to update SoD and Sensitive Access rule sets, unreversed temporary rules and conflicts on covid operations, improper change processes, . Changes in handling hybrid roles that blend duties, changes in sub-contractors, also administrators Sample some reviews to review the details of the certification: need to know, understanding, incompatibilities, review the removal of accesses
  6. Duplicated payments, errors and fraud split into smaller value POs to avoid additional approval checks Inaccurate client, vendor or bank master data to cleanup and training. incomplete or inaccurate sets of data Goods received after invoice date : goods receipts were posted after the date of inovices. Lack of resources in Warehouse is the main cause of late inventory accounting updates
  7. Attribute-Based Access Controls (ABAC) enable the use of “attributes” in authorization decisions. These attributes can be anything from user details such as role, department, nationality, or even a user’s security clearance level. You can consider additional contextual attributes such as IP address, location, time, device, and transaction history. And most importantly, for SoD, you can now use data attributes in authorization logic. This means that field-level values within SAP can be used to determine whether to block or allow a transaction, and these details can further be used in reporting activities.