<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: GRC ARA risk defined as critical in Financial Management Q&amp;A</title>
    <link>https://community.sap.com/t5/financial-management-q-a/grc-ara-risk-defined-as-critical/qaa-p/504889#M10707</link>
    <description>&lt;P&gt;Hello Sanna,&lt;/P&gt;
  &lt;P&gt;Firstly, no its not normal functionality and its not how GRC ARA should work.&lt;/P&gt;
  &lt;P&gt;Coming to your issue, could you please share few screen shots, your GRC SP level, it will help in better analysis.&lt;/P&gt;
  &lt;P&gt;Also, please cross check the rule IDs while executing risk analysis with the rule IDs of generated ruleset.&lt;/P&gt;
  &lt;P&gt;Kind regards,&lt;/P&gt;
  &lt;P&gt;Yashasvi&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2017 13:26:23 GMT</pubDate>
    <dc:creator>former_member226273</dc:creator>
    <dc:date>2017-11-29T13:26:23Z</dc:date>
    <item>
      <title>GRC ARA risk defined as critical</title>
      <link>https://community.sap.com/t5/financial-management-q-a/grc-ara-risk-defined-as-critical/qaq-p/504888</link>
      <description>&lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Hi,&lt;/P&gt;
  &lt;P&gt;Can you please confirm that this is how GRC Access control should work.&lt;/P&gt;
  &lt;P&gt;Here is the scenario:&lt;/P&gt;
  &lt;P&gt;We have few SOD risks defined as Critical (Risk level) . Those risks seem to behave in Risk Analysis like it would be a Critical action. By this we mean that we get results from the ad-hoc risk analysis even though the user/role does not have transaction codes from the both functions from the particular risk.&lt;/P&gt;
  &lt;P&gt;Example:&lt;/P&gt;
  &lt;P&gt;Risk ID: H005 (risk level Critical)&lt;/P&gt;
  &lt;P&gt;Function ID's: HR04 and PY04&lt;/P&gt;
  &lt;P&gt;The user is having transactions only from HR04, but usage of this function comes to the report. User does not have ANY transactions from the PY04.&lt;/P&gt;
  &lt;P&gt;This happens to multiple users. This does not happen if the Risk level of the SOD risk is something else than Critical.&lt;/P&gt;
  &lt;P&gt;Is this normal functionality of ARA risk analysis?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 10:54:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/financial-management-q-a/grc-ara-risk-defined-as-critical/qaq-p/504888</guid>
      <dc:creator>sanneval1</dc:creator>
      <dc:date>2017-11-27T10:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: GRC ARA risk defined as critical</title>
      <link>https://community.sap.com/t5/financial-management-q-a/grc-ara-risk-defined-as-critical/qaa-p/504889#M10707</link>
      <description>&lt;P&gt;Hello Sanna,&lt;/P&gt;
  &lt;P&gt;Firstly, no its not normal functionality and its not how GRC ARA should work.&lt;/P&gt;
  &lt;P&gt;Coming to your issue, could you please share few screen shots, your GRC SP level, it will help in better analysis.&lt;/P&gt;
  &lt;P&gt;Also, please cross check the rule IDs while executing risk analysis with the rule IDs of generated ruleset.&lt;/P&gt;
  &lt;P&gt;Kind regards,&lt;/P&gt;
  &lt;P&gt;Yashasvi&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 13:26:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/financial-management-q-a/grc-ara-risk-defined-as-critical/qaa-p/504889#M10707</guid>
      <dc:creator>former_member226273</dc:creator>
      <dc:date>2017-11-29T13:26:23Z</dc:date>
    </item>
  </channel>
</rss>

