cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

GRC Mitigating Controls

Former Member
0 Likes
1,029

Hi,

We are putting together our mitigating controls for the SOD issues in GRC. We are having problems trying to identify the reports that would give us the information to ensure that no user has violated a control. For example: S001Chg credit limit of marginal cust & manage SOs in it's favor - we need to get a list of changes made to the credit limits for each customer by user and compare that to the list of sales orders created / chnaged by the same user for the same customer.

The table that stores te credit limit changes is very big and a query on this each month wold probably time out.

Does anyone have any suggestions or previous experience on setting up mitigating controls and can give a high level view of the approch to take - i.e. should we be looking at standard SAP reports or should we create the reports using ABAPs or are there any other alternatives?

Thanks

Loretta

View Entire Topic
hkaur
Product and Topic Expert
Product and Topic Expert
0 Likes

Hello Loretta,

All you need to do to mitigate a risk is to 1) Create a mitigation control from the Mitigation tab

2) In the risk analysis report , select the risk and assign this mitigation control

Does this answer your query?

Harleen

GRC RIG

Former Member
0 Likes

Hi Harleen,

I have a question for you about mitigating controls, and it's non technical. I have all the GRC functionality working, but my client wants to know a good way to manage the controls.

Do you have some best practice information on what sort of information should be collected/retained/defined in order to have a good mitigating control in place?

Thanks,

Santosh