SlideShare ist ein Scribd-Unternehmen logo
1 von 14
Security and
governance
done right
Prof. Hernan Huwyler, MBA CPA
Agenda
Centralize risk-based controls
SAP GRC to simplify compliance
Streamline access certifications
Monitor with red flags analytics
Manage segregation of duties rulesets
The centralization of
processes is a
prerequisite for cost
saving and digitalization
efforts in response to the
COVID19 crisis
GRPC_STR_CHANGE
Update and simplify the
hierarchy of SAP processes
and sub-processes
GRPCRTA_PC
Centralize local
control catalogs with
harmonized multi-
compliance
frameworks
ASGN-TSTER
Change the schedule
of controls with
problematic
workflows
SURVEY
Align control surveys to
yes/no confirmations with
comments and attachments
The detection and
investigation of
suspicious fraudulent
activity is critical
during the operational
adjustments triggered by
COVID19
The economic crisis
requires to closely
monitor partners for
performance, solvency and
service continuity risks
SAP Business Partner
Screening
Ongoing due diligence on
third-parties
SAP Business Integrity
Screening
Notifications on fraud red
flags
SAP Tax Compliance
Prevent fines and disputes
SAP Risk Management
Develop exit plans to
address continuiry risks
SAP Risk Management
Monte Carlo Simulations
• cash-flow analysis
• delays in supply
• delays in orders
• budgeting
• insurance
• price calculation
• bidding
• Update process owners
• Compare changes in the most
used roles
User access reviews
• Evaluate recent changes for
terminations and contractors
• Sample some reviews to
audit the full process
The operational changes
during COVID19 triggered
numerous inconsistencies
in SAP data for cleanup
SAP Business Integrity
Screening
Exception reporting and
management
• Duplicated payments
• Split orders
• Invoice before reception
• Inaccurate master data
• Unusual discounts
SAP
Segregation of
duties
Ruleset
• Review changes in the
access control attributes
• Leverage checks based
on pre-configured SAP
Best Practices for
industry
• Continue improving the
rules for display rights
• Simplify roles for the new
normal
Let´s connect
Prof. Hernan Huwyler
/in/hernanwyler/
hewyler
Leading analysts on information
security in the era of digital
transformation
@kuppingercole
info@kuppingercole.com

Weitere ähnliche Inhalte

Was ist angesagt?

Let me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this yearLet me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this yearHernan Huwyler, MBA CPA
 
Managing Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus CrisisManaging Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus CrisisHernan Huwyler, MBA CPA
 
Qa Financials - 10 Smart Controls for Software Development
Qa Financials  - 10 Smart Controls for Software DevelopmentQa Financials  - 10 Smart Controls for Software Development
Qa Financials - 10 Smart Controls for Software DevelopmentHernan Huwyler, MBA CPA
 
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler, MBA CPA
 
Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Hernan Huwyler, MBA CPA
 
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...Hernan Huwyler, MBA CPA
 
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance RisksHernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance RisksHernan Huwyler, MBA CPA
 
Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340Hernan Huwyler, MBA CPA
 
AReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature EnoughAReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature EnoughHernan Huwyler, MBA CPA
 
Altran Financial Services
Altran Financial ServicesAltran Financial Services
Altran Financial Servicesianthm
 
ClockworkISMS
ClockworkISMSClockworkISMS
ClockworkISMSDelaney
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard Jim Robins
 
Effective Security Metrics
Effective Security MetricsEffective Security Metrics
Effective Security MetricsInnoTech
 
Supplier Management- HICX Solutions
Supplier Management- HICX SolutionsSupplier Management- HICX Solutions
Supplier Management- HICX SolutionsRohini Sharma
 
Implementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan HuwylerImplementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan HuwylerHernan Huwyler, MBA CPA
 
RISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — DoesRISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — DoesTechPoint
 
SafePaaS AuditPaaS
SafePaaS AuditPaaS SafePaaS AuditPaaS
SafePaaS AuditPaaS Jane Jones
 

Was ist angesagt? (20)

Let me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this yearLet me guess covid will be in all top risk studies this year
Let me guess covid will be in all top risk studies this year
 
Managing Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus CrisisManaging Contract Risks during Coronavirus Crisis
Managing Contract Risks during Coronavirus Crisis
 
Qa Financials - 10 Smart Controls for Software Development
Qa Financials  - 10 Smart Controls for Software DevelopmentQa Financials  - 10 Smart Controls for Software Development
Qa Financials - 10 Smart Controls for Software Development
 
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized World
 
Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks
 
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
10 Risk Techniques to Use Before you Die IE Business School IE Law School Pro...
 
RAP GC 2016
RAP GC 2016RAP GC 2016
RAP GC 2016
 
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance RisksHernan Huwyler Corporate Risk Assesstment Compliance Risks
Hernan Huwyler Corporate Risk Assesstment Compliance Risks
 
Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340
 
AReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature EnoughAReNA - Debate Is Machine Learning Mature Enough
AReNA - Debate Is Machine Learning Mature Enough
 
Altran Financial Services
Altran Financial ServicesAltran Financial Services
Altran Financial Services
 
ClockworkISMS
ClockworkISMSClockworkISMS
ClockworkISMS
 
CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard CML Group GRCaaS Dashboard
CML Group GRCaaS Dashboard
 
Effective Security Metrics
Effective Security MetricsEffective Security Metrics
Effective Security Metrics
 
Supplier Management- HICX Solutions
Supplier Management- HICX SolutionsSupplier Management- HICX Solutions
Supplier Management- HICX Solutions
 
Implementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan HuwylerImplementing, Documenting and Testing Compliance Controls Hernan Huwyler
Implementing, Documenting and Testing Compliance Controls Hernan Huwyler
 
RISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — DoesRISK: When What Can Never Happen — Does
RISK: When What Can Never Happen — Does
 
GP for Risk Management product sheet
GP for Risk Management product sheetGP for Risk Management product sheet
GP for Risk Management product sheet
 
Thematic compliance
Thematic complianceThematic compliance
Thematic compliance
 
SafePaaS AuditPaaS
SafePaaS AuditPaaS SafePaaS AuditPaaS
SafePaaS AuditPaaS
 

Ähnlich wie Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA

Operational Transformation in Banking Operations
Operational Transformation in Banking OperationsOperational Transformation in Banking Operations
Operational Transformation in Banking OperationsRajeev De Roy
 
ERP for Manufacturing Industry
ERP for Manufacturing IndustryERP for Manufacturing Industry
ERP for Manufacturing Industryvelcomerp
 
Telecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc eraTelecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc eraEhtisham Rao
 
Delivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and LogisticsDelivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and LogisticsSAP Technology
 
Evaluating and improving business process
Evaluating and improving business processEvaluating and improving business process
Evaluating and improving business processdutconsult
 
GRC: Identify and reduce business risks
GRC: Identify and reduce business risksGRC: Identify and reduce business risks
GRC: Identify and reduce business riskswrite2kanika
 
Managed Services Using SLAs and KPIs
Managed Services Using SLAs and KPIsManaged Services Using SLAs and KPIs
Managed Services Using SLAs and KPIsProlifics
 
Propeotech solution
Propeotech solutionPropeotech solution
Propeotech solutionbhuppi
 
Multi Vendor Management
Multi Vendor ManagementMulti Vendor Management
Multi Vendor ManagementMuratSelcuk
 
Accenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A ServiceAccenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A Serviceaccenture
 
Managing Today’s Supply Chain
Managing Today’s Supply ChainManaging Today’s Supply Chain
Managing Today’s Supply Chainmubarak2009
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Hernan Huwyler, MBA CPA
 
How To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global DeploymentHow To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global Deploymentdreamforce2006
 
Cloudway sipm capabilities
Cloudway sipm capabilitiesCloudway sipm capabilities
Cloudway sipm capabilitiesSaumya S
 
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...SAP Customer Experience
 
Automating Key Accountancy Processes
Automating Key Accountancy ProcessesAutomating Key Accountancy Processes
Automating Key Accountancy ProcessesBlackLine
 
Delivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for TelecommunicationDelivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for TelecommunicationSAP Technology
 
Quality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance MeasurementQuality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance Measurementmubarak2009
 

Ähnlich wie Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA (20)

Operational Transformation in Banking Operations
Operational Transformation in Banking OperationsOperational Transformation in Banking Operations
Operational Transformation in Banking Operations
 
GRC
GRCGRC
GRC
 
ERP for Manufacturing Industry
ERP for Manufacturing IndustryERP for Manufacturing Industry
ERP for Manufacturing Industry
 
Telecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc eraTelecom Billing's evolving role in post pc era
Telecom Billing's evolving role in post pc era
 
Delivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and LogisticsDelivering Real-Time Business Value for Cargo Transportation and Logistics
Delivering Real-Time Business Value for Cargo Transportation and Logistics
 
Evaluating and improving business process
Evaluating and improving business processEvaluating and improving business process
Evaluating and improving business process
 
GRC: Identify and reduce business risks
GRC: Identify and reduce business risksGRC: Identify and reduce business risks
GRC: Identify and reduce business risks
 
Money Saving
Money SavingMoney Saving
Money Saving
 
Managed Services Using SLAs and KPIs
Managed Services Using SLAs and KPIsManaged Services Using SLAs and KPIs
Managed Services Using SLAs and KPIs
 
Propeotech solution
Propeotech solutionPropeotech solution
Propeotech solution
 
Multi Vendor Management
Multi Vendor ManagementMulti Vendor Management
Multi Vendor Management
 
Accenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A ServiceAccenture Regulatory Reporting As A Service
Accenture Regulatory Reporting As A Service
 
Managing Today’s Supply Chain
Managing Today’s Supply ChainManaging Today’s Supply Chain
Managing Today’s Supply Chain
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
 
How To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global DeploymentHow To Drive a Large Scale, Global Deployment
How To Drive a Large Scale, Global Deployment
 
Cloudway sipm capabilities
Cloudway sipm capabilitiesCloudway sipm capabilities
Cloudway sipm capabilities
 
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
Digital Transformation Journey at Sealed Air Leveraging SAP Solutions for Cus...
 
Automating Key Accountancy Processes
Automating Key Accountancy ProcessesAutomating Key Accountancy Processes
Automating Key Accountancy Processes
 
Delivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for TelecommunicationDelivering Real-Time Business Value for Telecommunication
Delivering Real-Time Business Value for Telecommunication
 
Quality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance MeasurementQuality Assurance & Post Award Performance Measurement
Quality Assurance & Post Award Performance Measurement
 

Mehr von Hernan Huwyler, MBA CPA

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfHernan Huwyler, MBA CPA
 
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsProf Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsHernan Huwyler, MBA CPA
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceHernan Huwyler, MBA CPA
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler, MBA CPA
 
The Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfThe Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfHernan Huwyler, MBA CPA
 
Compliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerCompliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerHernan Huwyler, MBA CPA
 
DPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksDPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksHernan Huwyler, MBA CPA
 
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerMaster in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerHernan Huwyler, MBA CPA
 
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler, MBA CPA
 
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?Hernan Huwyler, MBA CPA
 
10 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 3730110 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 37301Hernan Huwyler, MBA CPA
 
Information Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksInformation Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksHernan Huwyler, MBA CPA
 
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento Hernan Huwyler, MBA CPA
 
IDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk dataIDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk dataHernan Huwyler, MBA CPA
 
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimientoUCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimientoHernan Huwyler, MBA CPA
 
Master Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan HuwylerMaster Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan HuwylerHernan Huwyler, MBA CPA
 
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapProf- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapHernan Huwyler, MBA CPA
 

Mehr von Hernan Huwyler, MBA CPA (20)

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
 
Model to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdfModel to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdf
 
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsProf Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
 
The Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfThe Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdf
 
R is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using RR is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using R
 
Compliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerCompliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan Huwyler
 
DPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksDPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy Risks
 
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerMaster in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
 
Cyber Laundering and the AML Directives
Cyber Laundering and the AML DirectivesCyber Laundering and the AML Directives
Cyber Laundering and the AML Directives
 
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
 
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
 
10 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 3730110 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 37301
 
Information Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksInformation Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT Risks
 
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
 
IDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk dataIDA DTU RiskLab How to validate your risk data
IDA DTU RiskLab How to validate your risk data
 
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimientoUCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
UCM Prof. Hernan Huwyler - Argentina Gesión de Riesgos de cumplimiento
 
Master Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan HuwylerMaster Class Compliance as a Service Hernan Huwyler
Master Class Compliance as a Service Hernan Huwyler
 
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapProf- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
 

Kürzlich hochgeladen

7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...Any kyc Account
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Roomdivyansh0kumar0
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒anilsa9823
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 

Kürzlich hochgeladen (20)

7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 

Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA

  • 2. Agenda Centralize risk-based controls SAP GRC to simplify compliance Streamline access certifications Monitor with red flags analytics Manage segregation of duties rulesets
  • 3. The centralization of processes is a prerequisite for cost saving and digitalization efforts in response to the COVID19 crisis
  • 4. GRPC_STR_CHANGE Update and simplify the hierarchy of SAP processes and sub-processes GRPCRTA_PC Centralize local control catalogs with harmonized multi- compliance frameworks ASGN-TSTER Change the schedule of controls with problematic workflows SURVEY Align control surveys to yes/no confirmations with comments and attachments
  • 5. The detection and investigation of suspicious fraudulent activity is critical during the operational adjustments triggered by COVID19
  • 6. The economic crisis requires to closely monitor partners for performance, solvency and service continuity risks
  • 7. SAP Business Partner Screening Ongoing due diligence on third-parties SAP Business Integrity Screening Notifications on fraud red flags SAP Tax Compliance Prevent fines and disputes SAP Risk Management Develop exit plans to address continuiry risks
  • 8. SAP Risk Management Monte Carlo Simulations • cash-flow analysis • delays in supply • delays in orders • budgeting • insurance • price calculation • bidding
  • 9. • Update process owners • Compare changes in the most used roles User access reviews • Evaluate recent changes for terminations and contractors • Sample some reviews to audit the full process
  • 10. The operational changes during COVID19 triggered numerous inconsistencies in SAP data for cleanup
  • 11. SAP Business Integrity Screening Exception reporting and management • Duplicated payments • Split orders • Invoice before reception • Inaccurate master data • Unusual discounts
  • 12. SAP Segregation of duties Ruleset • Review changes in the access control attributes • Leverage checks based on pre-configured SAP Best Practices for industry • Continue improving the rules for display rights • Simplify roles for the new normal
  • 13. Let´s connect Prof. Hernan Huwyler /in/hernanwyler/ hewyler
  • 14. Leading analysts on information security in the era of digital transformation @kuppingercole info@kuppingercole.com

Hinweis der Redaktion

  1. security and governance done right - How to centralize risk-based controls in SAP GRC to simplify compliance - Tips to streamline access certifications and monitoring with red flags analytics - How to manage segregation of duties rulesets
  2. Hierarchy GRPC_STR_DISPLAY: Use the needs for reports following the C-level organization and the hierarchy of regulations, cannot centralize inconsistent processes, review with process owners the relevance, reassess the process to focus the resources Centralization: many control frameworks, follow group policies, assess the justification of having differetent controls in some entities, centralize the delegation of tasks for other users´ access rights. SAP and non-SAP applications. Use generic test plans for control clusters corporate, financial, IT, and industry-specific Schedule: evaluate the frequency to test controls, test shared controls by shared service centers, look for recurrent escalation of issues or rejected or pending.
  3. SAP GRC to simplify compliance: fraud, more risks from work from home How can we reduce risks from business partners, business integrity of partners Standard risk management should be done better (e.g- Credit Swiss dismissing the CRO)7 Need for a real management of risks, update and audit action plans, prevent hiding risks
  4. Scenario analysis using Monte Carlo enables you to select a list of risks, assign them to a random distribution, and decide on a distribution method for the number of losses involved (frequency). In this way, the system estimates the total aggregated loss (the sum) at risk for your simulation.
  5. Detect changes in uses to update SoD and Sensitive Access rule sets, unreversed temporary rules and conflicts on covid operations, improper change processes, . Changes in handling hybrid roles that blend duties, changes in sub-contractors, also administrators Sample some reviews to review the details of the certification: need to know, understanding, incompatibilities, review the removal of accesses
  6. Duplicated payments, errors and fraud split into smaller value POs to avoid additional approval checks Inaccurate client, vendor or bank master data to cleanup and training. incomplete or inaccurate sets of data Goods received after invoice date : goods receipts were posted after the date of inovices. Lack of resources in Warehouse is the main cause of late inventory accounting updates
  7. Attribute-Based Access Controls (ABAC) enable the use of “attributes” in authorization decisions. These attributes can be anything from user details such as role, department, nationality, or even a user’s security clearance level. You can consider additional contextual attributes such as IP address, location, time, device, and transaction history. And most importantly, for SoD, you can now use data attributes in authorization logic. This means that field-level values within SAP can be used to determine whether to block or allow a transaction, and these details can further be used in reporting activities.