global car and heavy equipment rental company, improves ... heavy_equipmen... · global car and...
TRANSCRIPT
Leverage T echnology:
Move Your Business Forward™
Enterprise Risk Management Financial Close Monitor Advanced Controls Catalog Enterprise Audit GRC Monitor
FulcrumWay Leading Provider of Enterprise Risk Assessment Mitigation and Remediation Solutions
Copyright ©. Fulcrum Information Technology, Inc. Give me a lever long enough and a fulcrum on which to place it, and I shall move the world - Archimedes
Global car and heavy equipment rental company, improves
employee productivity with ERP Role Designer/Monitor
www.fulcrumway.com Page 2 Copyright © FulcrumWay
FulcrumWay Intelligent, Integrated Instant Risk Management™
FulcrumWay: is the #1 End-to-End Provider of Enterprise Risk Management Expertise,
Solutions and Software Services for Oracle EBS, PeopleSoft and JDE customers with
over 200 Fortune-500 to Middle Market clients. Since 2003, we have successfully
assisted companies across all major industry segments.
Expertise: Risk Advisory Services. Advanced Controls Design for Enterprise Business
Applications. Best Practices for Risk Mitigation and Internal Controls Automation.
Audit, Compliance, Financial, Enterprise and Operational Risk Assessments. Risk
Remediation Services such as Segregation of Duties.
Packaged Solutions: FulcrumWay is the #1 choice of Oracle customers for Oracle GRC
Manager, GRC Controls and GRC Intelligence/OBIEE software implementation. Oracle
has certified us as the only partner with Accelerators for Oracle GRC. We also provide
Managed Services and Hosting for Oracle GRC applications.
Software Services: Risk Management Tools: Enterprise Risk Manager, Financial Close
Risk Manager, Risk Based Audit Manager, IT Risk Workbench, and Advanced Controls
Catalog. Data Management Tools: Rules Repository, DataProbe™ adaptors and Data
Hub.
USA Presence: Privately held Delaware Corporation with US offices in New York City,
Dallas and San Francisco
International Presence: in Chennai, Dubai, Kampala, London, Rome, Santiago,
Singapore
Introduction
www.fulcrumway.com Page 3 Copyright © FulcrumWay
Government Oil and Gas
Healthcare
Communications
Financial Services
Industrial
Equipment
Natural
Resources
Manufacturing
Retail
FulcrumWay Clients
High Tech
Our Experience
Media and
Entertainment Life Sciences
www.fulcrumway.com Page 4 Copyright © FulcrumWay
FulcrumWay™ Insight
Thought Leadership
Our Experience
Co-Authored GRC Book: First book on GRC for Oracle Applications
Executive Round Tables – GRC Solutions for Energy Industry, Houston, November 2012
OAUG GRC Solution Lab - April 7th – 11th Denver: GRC Case Studies and Best Practices
IIA - Presentations - Top Five Reasons for Automating Application Controls
Collaborate 13 – GRC Client Appreciation Dinner April 9th , 2013 Denver
Webcasts – GRC Best Practices, Trends and Expert Insight
Oracle Open World – Annual GRC Dinner on September 23rd , 2013 W Hotel San Francisco
LinkedIn –FulcrumWay Risk, Compliance and Audit Software Group
YouTube Podcasts – FulcrumWay Instant Insight in 10 min or less
www.fulcrumway.com Page 5 Copyright © FulcrumWay
Assess Risk
Detect
Violations
Analyze
Issues
Remediate
Issues
Implement
Corrective
Actions
Monitor
Application
Environment
Scope
Application
Controls
Sample
ERP
Data
Manage
Exceptions
Setup
Preventive
Controls
IT/Business
Control Teams Application Controls
Manager
Application
Security
Administrator
Application
Controls
Manager
Establish
Test
Environment
FulcrumWay™ Application Controls
Management Best Practices
www.fulcrumway.com Page 6 Copyright © FulcrumWay
Business Rules Repository - Advanced Application Controls
Financial Close Management Operations Management
Enterprise Risk Monitors
FulcrumWay Enterprise Risk Management Services
Risk Assessment Enterprise Survey Key Risk Indicators
Task Monitor
Variance Analytics Reconciliation Analytics
Enterprise Audit Manager Audit Planner
Controls Verification
HCM/HR Controls : (HR,PR)
Inte
llig
en
t In
teg
rate
d In
sta
nt
Compliance Certification
Risk Based Audit Management
Financial Controls: (GL,AP,AR,FA,CM)
Distribution Controls: (OM,INV,WMS,PO)
Supply Chain Controls : (ENG,QP,WIP,BOM)
Access Monitor Configuration
Monitor Incident Monitor
Database Vulnerabilities
GRC Monitor – Enterprise Data Security
Master Data Monitor
Control Analytics
Incident Monitor
Overview
FulcrumWay Core Technologies
DataProbe DataHub Monitors Rules Repository Rules Engine Transmitters
www.fulcrumway.com Page 7 Copyright © FulcrumWay
Global car and equipment rental company,
improves employee productivity
Our Client
Leader in the car and equipment rental businesses worldwide
Providing quality car rental service for over 90 years.
Over 30,000 employees
Challenges Replace multiple legacy systems with one ERP solution Improved Segregation of Duty controls within mission critical applications Maintain consistent ERP system access roles across the subsidiaries leveraging the shared services model Increase external auditor’s reliance on ERP Access Controls Monitoring
Solutions
GRC DataProbe
ERP Controls Catalog
ERP Roles Monitor
Results: Reduce ERP Role design, build, testing and implementation time by 80% resulting in over $200,000 cost savings during ERP system implementation and global roll-out. Created over 100 Segregation of Duty compliant Roles by business segment with two weeks from FulcrumWay Role Templates within the controls catalog. Lowered ERP Total Cost of Ownership by reducing SoD remediation time and costs by ensuring that all users a assigned only the pre-approved Roles Improve SoD and Access Controls testing time by providing auditors the access log reports showing all Update, Review and Approve Role design changes. Accelerated ERP testing and deploying time by identifying SOD conflicts before the Roles are assigned to Users.
Client case
www.fulcrumway.com Page 8 Copyright © FulcrumWay
ERP Roles Manager Features
Role Manager is an ERP security design tool
Contains a pre-configured catalog of roles which comply with
segregation of duty (SOD) policies.
Roles by ERP module and typical access requirements for those
modules such as Manager, Supervisor, Clerk, Inquiry, Business
Setup and IT Setup.
You can use this tool to view existing role templates and design new
roles by easily selecting or deselecting ERP functions/transaction.
Once you complete the roles design, you can send it, using
workflows, to pre-assigned reviewers and approvers to finalize the
roles.
The role preparers, reviewers and approvers can also assess the
SOD control risks before finalizing the roles.
Leverage FW DataProbe/Scripts to load current Roles
Secure Access from fulcrumway.com portal
www.fulcrumway.com Page 9 Copyright © FulcrumWay
Access to Roles Manager Roles Manager
Sign in at fulcrumway.com
www.fulcrumway.com Page 10 Copyright © FulcrumWay
Access to Roles Manager Roles Manager
Select the Access Monitor Icon. Then click on the Maintain Access Roles Tab
www.fulcrumway.com Page 11 Copyright © FulcrumWay
Access to Roles Manager Roles Manager
Use a “source” role to create a new “target” role. View existing SOD issues with the “source” role. Assign Reviewers and Approvers for the role
www.fulcrumway.com Page 12 Copyright © FulcrumWay
Access to Roles Manager Roles Manager
Select / Deselect business activities to update Role configuration automatically
www.fulcrumway.com Page 13 Copyright © FulcrumWay
Access to Roles Manager Roles Manager
Select / Deselect Report Sets to update Role configuration automatically
www.fulcrumway.com Page 14 Copyright © FulcrumWay
Access to Roles Manager Roles Manager
Review and approve Roles – Email notifications