cancel
Showing results for 
Search instead for 
Did you mean: 

GRC Yearly Ruleset Review & Completeness and Accuracy

former_member245311
Participant
0 Kudos
661

Dear Friends, We are in the process of building a process to review changes done with GRC rule set ( as per below audit request ).

Provide evidence of the first 2018 review of changes to the rulesets. Please be sure to include assessment of the completeness and accuracy of the listing utilized for the review.

I would request your insights for: -

* What should be reviewed \ captured to find the changes done with GRC ruleset for a specific year.

* What are the aspects which need to be included \ captured in GRC ruleset completeness and accuracy documentation.

Or

Please reference any help documentation which would help in building process for this review.

Thanks

Raj

Accepted Solutions (0)

Answers (1)

Answers (1)

alessandr0
Active Contributor
0 Kudos

Hi Raj,

how do you perform changes to your rule set? Do you change in dev/quality and transport to prod? If so, you might have a change management process with transport approvals, etc. Or do you change directly in prod? Then you might use (or you should consider using) the risk and function change workflows that are pre-delivered by SAP. If neither, you can use the Change Log Report (from NWBC > Reports & Analytics) to find the changes to your rule set and report based on that. That simply shows all the changes performed.

Hope that helps.

Cheers, Alessandro