SlideShare a Scribd company logo
>
GRC
A BearingPoint Accelerator
Working closely with the client, we deliver a rigorous and
effective integrated GRC (Governance, Risk and
Compliance) solution – one that is not only right for the
client, but also available for them.
Contents
Market Drivers
Our Approach
Client Benefits
References
Contact
CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
Market Drivers
Organizations are facing ever-increasing global, local, and industry-specific regulatory challenges.
These challenges have been cumbersome to meet with manual, non-structured efforts in the past - but
with mounting complexities and quantities of regulatory requirements, this becomes impossible.
Organizations need to structure their compliance activities and consider how automation can help
them manage regulatory compliance effectively.
In some areas, with the availability of automated tools, regulators intensify their regulatory
requirements in such a way that impacted organizations have no choice but to use such automated
tools and processes - for example within the area of Anti Money Laundering.
Beyond the external requirements brought forward by regulators, organizations understand more and
more that GRC is not only a cost and a compliance topic, but it can also help shape a more effective,
more streamlined and more transparent organization.
GRC functions are increasingly becoming integrated within the discipline and they connect across
other disciplines such as the finance function.
CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
Market Drivers
Companies face many sources of risk - what
could go wrong, what will go wrong
CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
Risk Sources in Context of PESTEL Analysis: Political, Economic,
Social, Technological, Environmental and Legislative.
Supply Stability
• Bankruptcy of suppliers
Information Security
• Swiss National Bank
• LGT
Theft
• Retail companies typically loose about
10 % of products because of theft
Incorrect Financial Statements
• Enron (2001)
• Worldcom (2002)
• Parmalat (2003)
Environmental Risk
• BP Deepwater Horizon (2010)
• Tepko (Fukushima)
Others (Reputation)
• Shell
• Total
• Glencore
Non Compliance (with Regulation)
• Collaboration
External Fraud
• Google (Chinese environment)
• SecureID
Internal Fraud
• Societe General (2008)
• UBS (2011)
• Gate Group
Market Drivers
Fragmented, manual activities increase cost
and fail to provide strategic value
CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
Executive Management
Lack of Transparency
• Poor visibility into enterprise risk exposure
• Processes are too reactive and defensive
• Fragmentation limits effectiveness of risk
and compliance initiatives
Compliance, Risk and Audit
Lack of resources
• Limited time and personnel to effectively
manage risk and compliance
• Inefficient and costly manual processes
• Inability to proactively mitigate risk events
Business Owners
Lack of Alignment
• Risk and compliance management processes
are not embedded within the business
• Controls are not aligned to key risks
• Limited risk and compliance influence on
business decisions
Our Approach
Based on our SAP©-based GRC R2Go© solution and our experienced consultants, we provide help and guidance every step of
the way – from the overall GRC strategy to specific actions, for example to maintain the right level of access control. We take an
active collaborative approach across the key stages: scoping, blueprinting, implementation, testing, training, and go live. Early on
in the process, we make sure we truly reflect our client's particular situation and issues so that we have a rich and robust scope
rooted in the business, providing the foundation for a faster, more effective solution.
We are constantly evolving our GRC solution to ensure it keeps pace with the most recent developments and delivers the best
possible support. To this end, we work closely with SAP© to take account of new features and functions of the core GRC
software, so we can build as much as possible into our integrated solution.
Furthermore, we maintain relationships with top software vendors within the GRC market to assist clients in choosing the GRC
platform that best fits their needs.
CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
Our Approach
Comprehensive GRC Cycle
CLIENTBENEFITSOUR APPROACHMARKETDRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
Enterprise Risk Management
• Risk Identification
• Risk Response Management
• Risk Reporting
Compliance Management
• Policy Management
• Control Automation
Fraud Management
• Fraud Detection
• Case Management
• Fraud Reporting
IT & Access Risk Management
• Segregation of Duties
• Compliant Identity Management
Client Benefits
With our SAP©-based GRC R2Go© solution, clients can quickly and confidently meet their requirements across four core areas:
Risk Management, Process Control, Access Control and Fraud Management. Uniquely, clients can take all four areas as an
integrated solution to maximize the ease and effectiveness of their risk management and mitigation. We also offer the flexibility
to use one or more areas separately.
Risk catalogues, best practice processes, sample organizational structures and more – we have added a high degree of rich
content across all core areas. This content is drawn from our wide-ranging experience of managing risks across different sectors.
We enable our clients to take advantage of our integrated solution across the entire project lifecycle from scoping to training, to
truly accelerate their GRC initiatives.
CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
References
Project details
• Adaptive solution to manage increasing
data amounts and complexity
• Real time reporting and one click
consolidation features
• Integrate GRC cycle from Access,
Compliance and Risk Management
• Understanding Compliance and Risk
Management and bringing expertise
BearingPoint achievement
• Gather the requirements (workshops with stakeholders)
• Align the solution with the key stakeholders
• Build up a specific prototype to visualize potential
solutions
• Assess the financial impacts of key requirements and
illustrate potential solutions
• Close relationship to SAP to discuss enhancements to
product needed to meet requirements
Client results
• SAP GRC 10.0 Process Control and Risk
Management Blueprint
• Prototype equipped with master data
• Business Processes adapted to the needs but
aligned to SAP product capabilities
• Good understanding of the product for the involved
team
• User Management Integration scenario
Project details
• Develop and implement comprehensive
governance for the SAP user- and
authorization management for all
administration entities.
• The chosen software solution ensures
compliance to the SAP governance,
given the complex environment.
• Raise the Internal Control System
awareness.
• Choosing a particular software.
BearingPoint achievement
• Organizing workshops to gather requirements
• Develop a governance document aligned to business
needs
• Develop and implement a SAP GRC AC 10.0
prototype with the following components
- Access Risk Analysis (ARA)
- Access Request Management (ARM)
• Potential implementation scenarios
• Train stakeholders
Client results
• Fully working SAP GRC 10.0 AC prototype
• SAP Governance
• Business and IT rule set for Segregation of Duties
and critical authorizations
• Implementation scenarios and their financial
impact
• Basis for the software decision, linked with
know-how of the client prototype
SAP GRC 10 Process Control/Risk Management blueprint for a leading automotive supply manufacturer
BearingPoint was engaged to implement and integrate the Process Control and Risk Management modules of SAP`s GRC 10.0 solution.
BearingPoint is engaged to establish a GRC infrastructure in the SAP space which includes the definition of a governance, a client specific risk rule set and a SAP GRC 10.0 AC prototype.
Risk analysis concept and implementation in the public services environment
CLIENTBENEFITSOURAPPROACHMARKETDRIVERS REFERENCES CONTACT< >
GRC | A BearingPoint Accelerator
CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT<
Contact
Alexa Haisermann
Partner
BearingPoint Germany
alexa.haisermann@bearingpoint.com
Franz Hiller
Partner
BearingPoint Germany
franz.hiller@bearingpoint.com
GRC | A BearingPoint Accelerator
Oliver Engelbrecht
Partner
BearingPoint Germany
oliver.engelbrecht@bearingpoint.com
About BearingPoint
BearingPoint consultants understand that the world of business changes constantly and that the resulting complexities demand intelligent and
adaptive solutions. Our clients, whether in commercial or financial industries or in government, experience real results when they work with us. We
combine industry, operational and technology skills with relevant proprietary and other assets in order to tailor solutions for each client’s
individual challenges. This adaptive approach is at the heart of our culture and has led to long-standing relationships with many of the world’s
leading companies and organizations. Our global consulting network of 9,700 people serves clients in more than 70 countries and engages with
them for measurable results and long-lasting success.
For more information, please visit: www.bearingpoint.com
© 2015 BearingPoint. All rights reserved

More Related Content

What's hot

Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
jiricejka
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
Max Neira Schliemann
 
Integrated Risk Management 101
Integrated Risk Management 101Integrated Risk Management 101
Integrated Risk Management 101
Resolver Inc.
 
Introduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity FrameworkIntroduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity Framework
Tuan Phan
 
IT Risk Management
IT Risk ManagementIT Risk Management
IT Risk Management
Tudor Damian
 
Building an effective Information Security Roadmap
Building an effective Information Security RoadmapBuilding an effective Information Security Roadmap
Building an effective Information Security Roadmap
Elliott Franklin
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionRishabh Software
 
CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016
Hafiz Sheikh Adnan Ahmed
 
Governance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesGovernance, Risk, and Compliance Services
Governance, Risk, and Compliance Services
Capgemini
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating Model
Eryk Budi Pratama
 
Cyber Security IT GRC Management Model and Methodology.
Cyber Security IT GRC Management Model and Methodology.Cyber Security IT GRC Management Model and Methodology.
Cyber Security IT GRC Management Model and Methodology.
360factors
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
Transcendent Group
 
Introduction to Internal Controls and Control Self-Assessments (CSA)
Introduction to Internal Controls and Control Self-Assessments (CSA)Introduction to Internal Controls and Control Self-Assessments (CSA)
Introduction to Internal Controls and Control Self-Assessments (CSA)
Abdullah Mohammed
 
Third-Party Oversight & Governance
Third-Party Oversight & GovernanceThird-Party Oversight & Governance
Third-Party Oversight & Governance
EDR
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & complianceHR Globe Consulting
 
Corporate Compliance Overview
Corporate Compliance OverviewCorporate Compliance Overview
Corporate Compliance Overview
Sam Carr
 
A compliance officer's guide to third party risk management
A compliance officer's guide to third party risk managementA compliance officer's guide to third party risk management
A compliance officer's guide to third party risk management
SALIH AHMED ISLAM
 
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Alex Todd
 
GRC
GRCGRC

What's hot (20)

Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
 
Integrated Risk Management 101
Integrated Risk Management 101Integrated Risk Management 101
Integrated Risk Management 101
 
Introduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity FrameworkIntroduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity Framework
 
IT Risk Management
IT Risk ManagementIT Risk Management
IT Risk Management
 
Building an effective Information Security Roadmap
Building an effective Information Security RoadmapBuilding an effective Information Security Roadmap
Building an effective Information Security Roadmap
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016
 
Governance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesGovernance, Risk, and Compliance Services
Governance, Risk, and Compliance Services
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating Model
 
Cyber Security IT GRC Management Model and Methodology.
Cyber Security IT GRC Management Model and Methodology.Cyber Security IT GRC Management Model and Methodology.
Cyber Security IT GRC Management Model and Methodology.
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
 
Introduction to Internal Controls and Control Self-Assessments (CSA)
Introduction to Internal Controls and Control Self-Assessments (CSA)Introduction to Internal Controls and Control Self-Assessments (CSA)
Introduction to Internal Controls and Control Self-Assessments (CSA)
 
Third-Party Oversight & Governance
Third-Party Oversight & GovernanceThird-Party Oversight & Governance
Third-Party Oversight & Governance
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & compliance
 
Corporate Compliance Overview
Corporate Compliance OverviewCorporate Compliance Overview
Corporate Compliance Overview
 
FSI_Third Party Risk Management_Deloitte PoV
FSI_Third Party Risk Management_Deloitte PoVFSI_Third Party Risk Management_Deloitte PoV
FSI_Third Party Risk Management_Deloitte PoV
 
A compliance officer's guide to third party risk management
A compliance officer's guide to third party risk managementA compliance officer's guide to third party risk management
A compliance officer's guide to third party risk management
 
Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)Governance, Risk, Compliance & Trust (OCEG graphics removed)
Governance, Risk, Compliance & Trust (OCEG graphics removed)
 
GRC
GRCGRC
GRC
 

Viewers also liked

Revenue Recognition
Revenue RecognitionRevenue Recognition
Revenue Recognition
BearingPoint
 
LogCOST
LogCOSTLogCOST
LogCOST
BearingPoint
 
Cloud Navigator
Cloud NavigatorCloud Navigator
Cloud Navigator
BearingPoint
 
Active Manager
Active ManagerActive Manager
Active Manager
BearingPoint
 
Lean - ERP
Lean - ERPLean - ERP
Lean - ERP
BearingPoint
 
CLU
CLUCLU
CPQ - Configure, Price and Quoting Excellence
CPQ - Configure, Price and Quoting ExcellenceCPQ - Configure, Price and Quoting Excellence
CPQ - Configure, Price and Quoting Excellence
BearingPoint
 
IT Financial Management
IT Financial ManagementIT Financial Management
IT Financial Management
BearingPoint
 
Global Research: The Connected Industrial Workforce
Global Research: The Connected Industrial WorkforceGlobal Research: The Connected Industrial Workforce
Global Research: The Connected Industrial Workforce
accenture
 
IT M&A Advisory
IT M&A AdvisoryIT M&A Advisory
IT M&A Advisory
BearingPoint
 
Predictive Maintenance
Predictive MaintenancePredictive Maintenance
Predictive Maintenance
BearingPoint
 
Payment Factory
Payment FactoryPayment Factory
Payment Factory
BearingPoint
 

Viewers also liked (12)

Revenue Recognition
Revenue RecognitionRevenue Recognition
Revenue Recognition
 
LogCOST
LogCOSTLogCOST
LogCOST
 
Cloud Navigator
Cloud NavigatorCloud Navigator
Cloud Navigator
 
Active Manager
Active ManagerActive Manager
Active Manager
 
Lean - ERP
Lean - ERPLean - ERP
Lean - ERP
 
CLU
CLUCLU
CLU
 
CPQ - Configure, Price and Quoting Excellence
CPQ - Configure, Price and Quoting ExcellenceCPQ - Configure, Price and Quoting Excellence
CPQ - Configure, Price and Quoting Excellence
 
IT Financial Management
IT Financial ManagementIT Financial Management
IT Financial Management
 
Global Research: The Connected Industrial Workforce
Global Research: The Connected Industrial WorkforceGlobal Research: The Connected Industrial Workforce
Global Research: The Connected Industrial Workforce
 
IT M&A Advisory
IT M&A AdvisoryIT M&A Advisory
IT M&A Advisory
 
Predictive Maintenance
Predictive MaintenancePredictive Maintenance
Predictive Maintenance
 
Payment Factory
Payment FactoryPayment Factory
Payment Factory
 

Similar to GRC

Mann-India_SAP_Service-Offering_GRC
Mann-India_SAP_Service-Offering_GRCMann-India_SAP_Service-Offering_GRC
Mann-India_SAP_Service-Offering_GRC
Mann-India
 
Grom Capabilities 2016
Grom Capabilities 2016Grom Capabilities 2016
Grom Capabilities 2016Sue Linder
 
iGrafx | Business Process Management Solution Provider | ProServ UAE
iGrafx | Business Process Management Solution Provider | ProServ UAEiGrafx | Business Process Management Solution Provider | ProServ UAE
iGrafx | Business Process Management Solution Provider | ProServ UAE
ProServ
 
Chase Cooper Overview
Chase Cooper OverviewChase Cooper Overview
Chase Cooper OverviewAoife Brennan
 
A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC 
Aelum Consulting
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
Cognizant
 
Company Overview
Company OverviewCompany Overview
Company Overviewnetmongers
 
An Introduction to econsys
An Introduction to econsysAn Introduction to econsys
An Introduction to econsys
Andrew Redfern
 
GRC– The Way Forward
GRC– The Way ForwardGRC– The Way Forward
GRC– The Way Forward
Rochester Security Summit
 
The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field
Resolver Inc.
 
Product Development Plan
Product Development PlanProduct Development Plan
Product Development Plan
Osama Shaath
 
Cloudway sipm capabilities
Cloudway sipm capabilitiesCloudway sipm capabilities
Cloudway sipm capabilities
Saumya S
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear LLC
 
SAM Software Asset Management
SAM Software Asset ManagementSAM Software Asset Management
SAM Software Asset Management
BearingPoint
 
Acknowledging ServiceNow GRC's Potential for Transformation.pdf
Acknowledging ServiceNow GRC's Potential for Transformation.pdfAcknowledging ServiceNow GRC's Potential for Transformation.pdf
Acknowledging ServiceNow GRC's Potential for Transformation.pdf
Aelum Consulting
 
Software Performance Engineering Services
Software Performance Engineering ServicesSoftware Performance Engineering Services
Software Performance Engineering Services
Collaborative Consulting
 
SAP License Services by Crayon Software Experts
SAP License Services by Crayon Software ExpertsSAP License Services by Crayon Software Experts
SAP License Services by Crayon Software Experts
m. gravesteijn ? create & connect
 
Mann-India_Service-Offerings_IS-Mining
Mann-India_Service-Offerings_IS-MiningMann-India_Service-Offerings_IS-Mining
Mann-India_Service-Offerings_IS-Mining
Mann-India
 
CA ITSM & ITAM
CA ITSM & ITAMCA ITSM & ITAM
CA ITSM & ITAM
James Farley-Sutton
 
Esouag r12 presentation
Esouag r12 presentationEsouag r12 presentation
Esouag r12 presentation
Ishtiaq Khan
 

Similar to GRC (20)

Mann-India_SAP_Service-Offering_GRC
Mann-India_SAP_Service-Offering_GRCMann-India_SAP_Service-Offering_GRC
Mann-India_SAP_Service-Offering_GRC
 
Grom Capabilities 2016
Grom Capabilities 2016Grom Capabilities 2016
Grom Capabilities 2016
 
iGrafx | Business Process Management Solution Provider | ProServ UAE
iGrafx | Business Process Management Solution Provider | ProServ UAEiGrafx | Business Process Management Solution Provider | ProServ UAE
iGrafx | Business Process Management Solution Provider | ProServ UAE
 
Chase Cooper Overview
Chase Cooper OverviewChase Cooper Overview
Chase Cooper Overview
 
A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC 
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
 
Company Overview
Company OverviewCompany Overview
Company Overview
 
An Introduction to econsys
An Introduction to econsysAn Introduction to econsys
An Introduction to econsys
 
GRC– The Way Forward
GRC– The Way ForwardGRC– The Way Forward
GRC– The Way Forward
 
The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field
 
Product Development Plan
Product Development PlanProduct Development Plan
Product Development Plan
 
Cloudway sipm capabilities
Cloudway sipm capabilitiesCloudway sipm capabilities
Cloudway sipm capabilities
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
SAM Software Asset Management
SAM Software Asset ManagementSAM Software Asset Management
SAM Software Asset Management
 
Acknowledging ServiceNow GRC's Potential for Transformation.pdf
Acknowledging ServiceNow GRC's Potential for Transformation.pdfAcknowledging ServiceNow GRC's Potential for Transformation.pdf
Acknowledging ServiceNow GRC's Potential for Transformation.pdf
 
Software Performance Engineering Services
Software Performance Engineering ServicesSoftware Performance Engineering Services
Software Performance Engineering Services
 
SAP License Services by Crayon Software Experts
SAP License Services by Crayon Software ExpertsSAP License Services by Crayon Software Experts
SAP License Services by Crayon Software Experts
 
Mann-India_Service-Offerings_IS-Mining
Mann-India_Service-Offerings_IS-MiningMann-India_Service-Offerings_IS-Mining
Mann-India_Service-Offerings_IS-Mining
 
CA ITSM & ITAM
CA ITSM & ITAMCA ITSM & ITAM
CA ITSM & ITAM
 
Esouag r12 presentation
Esouag r12 presentationEsouag r12 presentation
Esouag r12 presentation
 

More from BearingPoint

Marketing Operations Grid
Marketing Operations GridMarketing Operations Grid
Marketing Operations Grid
BearingPoint
 
Transformation Model for leveraging ARTIFICIAL INTELLIGENCE
Transformation Model for leveraging ARTIFICIAL INTELLIGENCETransformation Model for leveraging ARTIFICIAL INTELLIGENCE
Transformation Model for leveraging ARTIFICIAL INTELLIGENCE
BearingPoint
 
Business and Data in motion
Business and Data in motionBusiness and Data in motion
Business and Data in motion
BearingPoint
 
Planning and Forecasting in Oil & Gas
Planning and Forecasting in Oil & GasPlanning and Forecasting in Oil & Gas
Planning and Forecasting in Oil & Gas
BearingPoint
 
Opex in Manufacturing
Opex in ManufacturingOpex in Manufacturing
Opex in Manufacturing
BearingPoint
 
Visual Analytics
Visual AnalyticsVisual Analytics
Visual Analytics
BearingPoint
 
360° B2B Sales Management
360° B2B Sales Management360° B2B Sales Management
360° B2B Sales Management
BearingPoint
 
Factory Navigator
Factory NavigatorFactory Navigator
Factory Navigator
BearingPoint
 
Connectivity for IoT
Connectivity for IoTConnectivity for IoT
Connectivity for IoT
BearingPoint
 
Lab Optimizer
Lab OptimizerLab Optimizer
Lab Optimizer
BearingPoint
 
Service goes digital
Service goes digitalService goes digital
Service goes digital
BearingPoint
 
Digital Workspace
Digital WorkspaceDigital Workspace
Digital Workspace
BearingPoint
 
Investment Accounting in the Cloud
Investment Accounting in the CloudInvestment Accounting in the Cloud
Investment Accounting in the Cloud
BearingPoint
 
Investment Data Warehouse
Investment Data WarehouseInvestment Data Warehouse
Investment Data Warehouse
BearingPoint
 
Universal Consor
Universal ConsorUniversal Consor
Universal Consor
BearingPoint
 

More from BearingPoint (15)

Marketing Operations Grid
Marketing Operations GridMarketing Operations Grid
Marketing Operations Grid
 
Transformation Model for leveraging ARTIFICIAL INTELLIGENCE
Transformation Model for leveraging ARTIFICIAL INTELLIGENCETransformation Model for leveraging ARTIFICIAL INTELLIGENCE
Transformation Model for leveraging ARTIFICIAL INTELLIGENCE
 
Business and Data in motion
Business and Data in motionBusiness and Data in motion
Business and Data in motion
 
Planning and Forecasting in Oil & Gas
Planning and Forecasting in Oil & GasPlanning and Forecasting in Oil & Gas
Planning and Forecasting in Oil & Gas
 
Opex in Manufacturing
Opex in ManufacturingOpex in Manufacturing
Opex in Manufacturing
 
Visual Analytics
Visual AnalyticsVisual Analytics
Visual Analytics
 
360° B2B Sales Management
360° B2B Sales Management360° B2B Sales Management
360° B2B Sales Management
 
Factory Navigator
Factory NavigatorFactory Navigator
Factory Navigator
 
Connectivity for IoT
Connectivity for IoTConnectivity for IoT
Connectivity for IoT
 
Lab Optimizer
Lab OptimizerLab Optimizer
Lab Optimizer
 
Service goes digital
Service goes digitalService goes digital
Service goes digital
 
Digital Workspace
Digital WorkspaceDigital Workspace
Digital Workspace
 
Investment Accounting in the Cloud
Investment Accounting in the CloudInvestment Accounting in the Cloud
Investment Accounting in the Cloud
 
Investment Data Warehouse
Investment Data WarehouseInvestment Data Warehouse
Investment Data Warehouse
 
Universal Consor
Universal ConsorUniversal Consor
Universal Consor
 

Recently uploaded

Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdfDigital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Jos Voskuil
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
HARSHITHV26
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
BBPMedia1
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
Ben Wann
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
tanyjahb
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
BBPMedia1
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
usawebmarket
 
BeMetals Presentation_May_22_2024 .pdf
BeMetals Presentation_May_22_2024   .pdfBeMetals Presentation_May_22_2024   .pdf
BeMetals Presentation_May_22_2024 .pdf
DerekIwanaka1
 
PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop.com LTD
 
What are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdfWhat are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdf
HumanResourceDimensi1
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
SynapseIndia
 
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
PaulBryant58
 
Brand Analysis for an artist named Struan
Brand Analysis for an artist named StruanBrand Analysis for an artist named Struan
Brand Analysis for an artist named Struan
sarahvanessa51503
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
KaiNexus
 
Attending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learnersAttending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learners
Erika906060
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
Cynthia Clay
 
Role of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in MiningRole of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in Mining
Naaraayani Minerals Pvt.Ltd
 
India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...
India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...
India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...
Kumar Satyam
 
Lookback Analysis
Lookback AnalysisLookback Analysis
Lookback Analysis
Safe PaaS
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
creerey
 

Recently uploaded (20)

Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdfDigital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
 
BeMetals Presentation_May_22_2024 .pdf
BeMetals Presentation_May_22_2024   .pdfBeMetals Presentation_May_22_2024   .pdf
BeMetals Presentation_May_22_2024 .pdf
 
PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024PriyoShop Celebration Pohela Falgun Mar 20, 2024
PriyoShop Celebration Pohela Falgun Mar 20, 2024
 
What are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdfWhat are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdf
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
Accpac to QuickBooks Conversion Navigating the Transition with Online Account...
 
Brand Analysis for an artist named Struan
Brand Analysis for an artist named StruanBrand Analysis for an artist named Struan
Brand Analysis for an artist named Struan
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
 
Attending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learnersAttending a job Interview for B1 and B2 Englsih learners
Attending a job Interview for B1 and B2 Englsih learners
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
Role of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in MiningRole of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in Mining
 
India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...
India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...
India Orthopedic Devices Market: Unlocking Growth Secrets, Trends and Develop...
 
Lookback Analysis
Lookback AnalysisLookback Analysis
Lookback Analysis
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 

GRC

  • 1. > GRC A BearingPoint Accelerator Working closely with the client, we deliver a rigorous and effective integrated GRC (Governance, Risk and Compliance) solution – one that is not only right for the client, but also available for them.
  • 2. Contents Market Drivers Our Approach Client Benefits References Contact CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator
  • 3. Market Drivers Organizations are facing ever-increasing global, local, and industry-specific regulatory challenges. These challenges have been cumbersome to meet with manual, non-structured efforts in the past - but with mounting complexities and quantities of regulatory requirements, this becomes impossible. Organizations need to structure their compliance activities and consider how automation can help them manage regulatory compliance effectively. In some areas, with the availability of automated tools, regulators intensify their regulatory requirements in such a way that impacted organizations have no choice but to use such automated tools and processes - for example within the area of Anti Money Laundering. Beyond the external requirements brought forward by regulators, organizations understand more and more that GRC is not only a cost and a compliance topic, but it can also help shape a more effective, more streamlined and more transparent organization. GRC functions are increasingly becoming integrated within the discipline and they connect across other disciplines such as the finance function. CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator
  • 4. Market Drivers Companies face many sources of risk - what could go wrong, what will go wrong CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator Risk Sources in Context of PESTEL Analysis: Political, Economic, Social, Technological, Environmental and Legislative. Supply Stability • Bankruptcy of suppliers Information Security • Swiss National Bank • LGT Theft • Retail companies typically loose about 10 % of products because of theft Incorrect Financial Statements • Enron (2001) • Worldcom (2002) • Parmalat (2003) Environmental Risk • BP Deepwater Horizon (2010) • Tepko (Fukushima) Others (Reputation) • Shell • Total • Glencore Non Compliance (with Regulation) • Collaboration External Fraud • Google (Chinese environment) • SecureID Internal Fraud • Societe General (2008) • UBS (2011) • Gate Group
  • 5. Market Drivers Fragmented, manual activities increase cost and fail to provide strategic value CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator Executive Management Lack of Transparency • Poor visibility into enterprise risk exposure • Processes are too reactive and defensive • Fragmentation limits effectiveness of risk and compliance initiatives Compliance, Risk and Audit Lack of resources • Limited time and personnel to effectively manage risk and compliance • Inefficient and costly manual processes • Inability to proactively mitigate risk events Business Owners Lack of Alignment • Risk and compliance management processes are not embedded within the business • Controls are not aligned to key risks • Limited risk and compliance influence on business decisions
  • 6. Our Approach Based on our SAP©-based GRC R2Go© solution and our experienced consultants, we provide help and guidance every step of the way – from the overall GRC strategy to specific actions, for example to maintain the right level of access control. We take an active collaborative approach across the key stages: scoping, blueprinting, implementation, testing, training, and go live. Early on in the process, we make sure we truly reflect our client's particular situation and issues so that we have a rich and robust scope rooted in the business, providing the foundation for a faster, more effective solution. We are constantly evolving our GRC solution to ensure it keeps pace with the most recent developments and delivers the best possible support. To this end, we work closely with SAP© to take account of new features and functions of the core GRC software, so we can build as much as possible into our integrated solution. Furthermore, we maintain relationships with top software vendors within the GRC market to assist clients in choosing the GRC platform that best fits their needs. CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator
  • 7. Our Approach Comprehensive GRC Cycle CLIENTBENEFITSOUR APPROACHMARKETDRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator Enterprise Risk Management • Risk Identification • Risk Response Management • Risk Reporting Compliance Management • Policy Management • Control Automation Fraud Management • Fraud Detection • Case Management • Fraud Reporting IT & Access Risk Management • Segregation of Duties • Compliant Identity Management
  • 8. Client Benefits With our SAP©-based GRC R2Go© solution, clients can quickly and confidently meet their requirements across four core areas: Risk Management, Process Control, Access Control and Fraud Management. Uniquely, clients can take all four areas as an integrated solution to maximize the ease and effectiveness of their risk management and mitigation. We also offer the flexibility to use one or more areas separately. Risk catalogues, best practice processes, sample organizational structures and more – we have added a high degree of rich content across all core areas. This content is drawn from our wide-ranging experience of managing risks across different sectors. We enable our clients to take advantage of our integrated solution across the entire project lifecycle from scoping to training, to truly accelerate their GRC initiatives. CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator
  • 9. References Project details • Adaptive solution to manage increasing data amounts and complexity • Real time reporting and one click consolidation features • Integrate GRC cycle from Access, Compliance and Risk Management • Understanding Compliance and Risk Management and bringing expertise BearingPoint achievement • Gather the requirements (workshops with stakeholders) • Align the solution with the key stakeholders • Build up a specific prototype to visualize potential solutions • Assess the financial impacts of key requirements and illustrate potential solutions • Close relationship to SAP to discuss enhancements to product needed to meet requirements Client results • SAP GRC 10.0 Process Control and Risk Management Blueprint • Prototype equipped with master data • Business Processes adapted to the needs but aligned to SAP product capabilities • Good understanding of the product for the involved team • User Management Integration scenario Project details • Develop and implement comprehensive governance for the SAP user- and authorization management for all administration entities. • The chosen software solution ensures compliance to the SAP governance, given the complex environment. • Raise the Internal Control System awareness. • Choosing a particular software. BearingPoint achievement • Organizing workshops to gather requirements • Develop a governance document aligned to business needs • Develop and implement a SAP GRC AC 10.0 prototype with the following components - Access Risk Analysis (ARA) - Access Request Management (ARM) • Potential implementation scenarios • Train stakeholders Client results • Fully working SAP GRC 10.0 AC prototype • SAP Governance • Business and IT rule set for Segregation of Duties and critical authorizations • Implementation scenarios and their financial impact • Basis for the software decision, linked with know-how of the client prototype SAP GRC 10 Process Control/Risk Management blueprint for a leading automotive supply manufacturer BearingPoint was engaged to implement and integrate the Process Control and Risk Management modules of SAP`s GRC 10.0 solution. BearingPoint is engaged to establish a GRC infrastructure in the SAP space which includes the definition of a governance, a client specific risk rule set and a SAP GRC 10.0 AC prototype. Risk analysis concept and implementation in the public services environment CLIENTBENEFITSOURAPPROACHMARKETDRIVERS REFERENCES CONTACT< > GRC | A BearingPoint Accelerator
  • 10. CLIENT BENEFITSOUR APPROACHMARKET DRIVERS REFERENCES CONTACT< Contact Alexa Haisermann Partner BearingPoint Germany alexa.haisermann@bearingpoint.com Franz Hiller Partner BearingPoint Germany franz.hiller@bearingpoint.com GRC | A BearingPoint Accelerator Oliver Engelbrecht Partner BearingPoint Germany oliver.engelbrecht@bearingpoint.com About BearingPoint BearingPoint consultants understand that the world of business changes constantly and that the resulting complexities demand intelligent and adaptive solutions. Our clients, whether in commercial or financial industries or in government, experience real results when they work with us. We combine industry, operational and technology skills with relevant proprietary and other assets in order to tailor solutions for each client’s individual challenges. This adaptive approach is at the heart of our culture and has led to long-standing relationships with many of the world’s leading companies and organizations. Our global consulting network of 9,700 people serves clients in more than 70 countries and engages with them for measurable results and long-lasting success. For more information, please visit: www.bearingpoint.com © 2015 BearingPoint. All rights reserved