oracle systems & control for financial org

37
1 Applications Segregation of Duties in Oracle

Upload: harish-sharma

Post on 18-Aug-2015

91 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Oracle systems & control  for  financial org

1

Risk Management in Role-based ApplicationsSegregation of Duties in Oracle

Page 2: Oracle systems & control  for  financial org

Problem agenda

Introduction P2P Issues that Impact the Bottom-Line Oracle Advanced Controls Solution Use Case: Financial Organization SystemsQ & A

Page 3: Oracle systems & control  for  financial org

3

Harish Sharma, Senior Consultant

Over 7 years of experience in ERP Implementation, Security and GRC Design

Page 4: Oracle systems & control  for  financial org

Problem agenda

Introduction P2P Issues that Impact the Bottom-Line Oracle Advanced Controls Solution Use Case: Financial Organization SystemsQ & A

Page 5: Oracle systems & control  for  financial org

What Do We Mean by Control ‘Issues’ 5

The processes that ensure: Efficient and effective operations Reliable and accurate reporting Fraud resistant operation Internal External Regulatory compliant

Page 6: Oracle systems & control  for  financial org

Common Issues: Duplicate Vendors in Master Vendor File

6 Duplicate payments

The invoice is submitted for entry twice Different options for receipt and payment of invoices, including outsourcing. Data entry errors Manual checks requests

Correspondence issues Supplier is using a different site/location. Duplicate Name problem with Supplier conversion

Internal control issue Controls Inappropriately configured Controls are not regularly overridden

AP processors take shortcuts when creating vendor entries Misreading a number or letter (for example: 0 instead of O, or 5 instead of S). Transposing numbers (for example: 56 instead of 65) Mis-keying (or simply omitting) punctuation (such as hyphens and slashes) Omitting leading or trailing zeroes

Segregation of duties concern Standardization and normalization are crucial Preventing creating new ones Identifying existing duplicate ones

Rigid coding standards

Page 7: Oracle systems & control  for  financial org

Problem agenda

Introduction P2P Issues that Impact the Bottom-Line Oracle Advanced Controls Solution Use Case: Financial Organization SystemsQ & A

Page 8: Oracle systems & control  for  financial org

Advanced Controls8

Layer of automated controls over ERP controls Continuously monitor key controls Detect and Report issues as they occur Prevent issues from occurring Quickly see high risk issues with exception based

dashboards Address issues that affect the bottom line Reduces operational risk and process effectiveness

Page 9: Oracle systems & control  for  financial org

9

Page 10: Oracle systems & control  for  financial org

10Copyright © Capgemini 2013. ll Rights Reserved

10

Page 11: Oracle systems & control  for  financial org
Page 12: Oracle systems & control  for  financial org

12Copyright © Capgemini 2013. ll Rights Reserved

Page 13: Oracle systems & control  for  financial org
Page 14: Oracle systems & control  for  financial org

Continuous Monitor – Duplicate Vendor

Page 15: Oracle systems & control  for  financial org

Incident Management

Page 16: Oracle systems & control  for  financial org

Control Definition

Page 17: Oracle systems & control  for  financial org

Preventive Measure

Page 18: Oracle systems & control  for  financial org

Preventive Measure Cont..

Page 19: Oracle systems & control  for  financial org

19Copyright © Capgemini 2013. ll Rights Reserved

Page 20: Oracle systems & control  for  financial org

20Copyright © Capgemini 2013. ll Rights Reserved

Page 21: Oracle systems & control  for  financial org

Problem agenda

Introduction P2P Issues that Impact the Bottom-Line Oracle Advanced Controls Solution Use Case: Financial Organization SystemsQ & A

Page 22: Oracle systems & control  for  financial org

22

Oracle Advanced Controls –Customer Experience

Page 23: Oracle systems & control  for  financial org
Page 24: Oracle systems & control  for  financial org

24

Page 25: Oracle systems & control  for  financial org

25

Page 26: Oracle systems & control  for  financial org

26

Page 27: Oracle systems & control  for  financial org

Use Case - Scope 27

Page 28: Oracle systems & control  for  financial org

Security Infrastructure

28

Page 29: Oracle systems & control  for  financial org

approach to GRC Projects29

Page 30: Oracle systems & control  for  financial org

Implementation Approach30

Page 31: Oracle systems & control  for  financial org

31

Page 32: Oracle systems & control  for  financial org

Tangible Business Benefits32Fewer duplicate payments: Vendor master cleanup eliminates the duplicate vendor files and vendor coding issues that significantly contribute to duplicate payments.

Reduced fraud: The Association of Certified Fraud Examiners estimates that the average company loses 5 percent of its annual revenues to fraud. Cleaning and maintaining a vendor master file provides the visibility and controls required to help reduce fraudulent payments.

Increased staff productivity: Clean vendor files make it easier to find vendors in your system. This makes it less likely that staff will create a duplicate vendor record, and ensures that staff does not waste their time maintaining files that should have been deleted.

Improved analysis and management of spending: By showing which vendors are parts of the same corporate entity, vendor master cleanup helps companies analyze and manage spending to negotiate better discount terms and proactively manage their debit balances.

Streamlined regulatory compliance: Vendor master data management drives compliance with regulations and internal controls, as well as compliance with 1099 tax legislation.

Reduced costs: Compared to traditional manual processes, an ongoing vendor master data maintenance program significantly reduces the costs of managing supplier information.

Page 33: Oracle systems & control  for  financial org

33

Thanking You

Page 34: Oracle systems & control  for  financial org

Q & A

Page 35: Oracle systems & control  for  financial org

35

Page 36: Oracle systems & control  for  financial org

36

Page 37: Oracle systems & control  for  financial org

37