Given the role of SAP in finance, SoD is an unavoidable responsibility for SAP administrators and others responsible for aligning SAP with GRC. Also make sure that all role changes must be analyzed and remediated before implementing. The outcome of this step is that your business has determined what is an unacceptable risk that they want to report on and manage wia remediation or mitigation. Access risks relate to the danger that an unauthorized outsider could access the company's digital assets. This document elaborates the SoD Management Process that is a key part to reduce Segregation of Duty (SoD) conflicts in a company. If one employee can set up the vendor in SAP, write the PO, approve the invoices and sign checks, that employee has the means to embezzle funds. Access Risk Analysis and SoD Risk Review does the hard work of mapping user roles to SAP software functions. See also: four eyes principle, risk avoidance, corporate governance, accounting error, regulatory compliance, compliance burden. Finally, establish a new continuous process wherein every access request is reviewed against the SoD conflict matrix prior to provisioning on the system. An SoD Matrix plots transaction permissions on the X and Y axes of a matrix.

There's also the potential for SoD risks in SAP and ultimately fraud. Done by hand, it's a big chore, so an automated solution can be highly beneficial. SoD involves breaking down tasks that might reasonably be completed by a single individual into multiple tasks so that no one person is solely in control. As part of GRC responsibilities, the IT department (or security team) will conduct a GRC access risk analysis. SoD Risk Review is the process of inspecting an organization's users, their roles and the underlying SAP system for situations where SoD violations are occurring.

A rulebook or ruleset, implemented with (and oftentimes included with) a GRC solution, is far more efficient and effective. SoD is a subset of the broader Governance, Risk Management and Compliance (GRC) functions of a business. Segregation of duties (SoD) is an internal control designed to prevent error and fraud by ensuring that at least two individuals are responsible for the separate parts of any task. However, as experience has shown, when there’s the potential for abuse, there is abuse more often than people want to admit. GRC is partly a board- and c-suite executive level responsibility that covers how well they’re governing the corporate entity. One that involves defining the organizational structure, mapping out transaction steps and correlating them with user roles. In the vendor-PO-invoice flow, the roles would correspond to each critical portion of the job function. Take a deep dive into options for Oracle E-Business Suite. Separation of duties (SoD; also known as Segregation of Duties) is the concept of having more than one person required to complete a task.