SAP GRC Overview Paul Pessutti Director, Strategic Applications SAP GRC
Managing Risk Is Everyone s Job Board, Audit Committee Executive compensation issues Executives & Managers Incomplete global risk profile Compliance / Risk Office Disconnected risk analysis IT Operations Data security issues Procurement Supplier black lists? Sales, Finance Complex, international compliance requirements Human Resources Employee safety compliance Service High credit risk customers Supply Chain Customers & Channel
Unidentified risks impact performance National Headlines US Imposes Record $100 Million Penalty for Export Control Violations March 27, 2007, Washington Post Data Theft at Nuclear Agency Went Unreported for 9 Months June 10, 2006, New York Times Bomb Scare shuts Port s Terminal 18 Aug 18, 2006, The Seattle Times Brand Name High Tech Manufacturer Violates E.U. Pollution Law Jul 06, 2006, CIO Tech Informer Increases Business Costs Reduces Investor & Market Confidence Disrupts major operations Impacts Performance in the Market Results in Closer Scrutiny Impairs Customer Service Failure in Operational Control
Overcome fragmentation, gain transparency with GRC Board, Audit Committee Evidence for decisions & directives Compliance / Risk Office Integrated risk analysis IT Operations Secure IT infrastructure Procurement Anti-terrorist trade practices SALARIES Executives & Managers Increased confidence in business results Finance Global financial reporting compliance Human Resources Environmental health & safety compliance Sales, Service Balanced credit profile Supply Chain Customers & Channel
A holistic solution for GRC Automates and embeds GRC processes into business processes Business Process SAP Solutions for GRC Industry-Specific GRC Cross-Industry GRC GRC Repository: Documentation and Monitoring Risk Access Controls Global Trade Environment Process Controls Business Process Platform Service Partners Technology Partners Content Partners Delivers transparency for balanced global risk profile Standardizes on common GRC content and rules Drives higher margins and shareholder value Business Applications Promotes a culture which values effective GRC
GRC Business Drivers Governance Risk Risk and and Compliance Financial Financial Compliance Compliance Trade Trade Environment Environment Regulations Regulations SOX SOX mandate mandate (Section (Section 404 404 and and 302) 302) Segregation Segregation of of Duties Duties analysis analysis & & enforcement enforcement Reduce Reduce fraud fraud and and risk risk Certify Certify the the sign-off sign-off process process for for executives executives Identify Identify controls controls for for organizations organizations Provide Provide auditors auditors with with complete complete audit audit trail trail Enforcement is on the Enforcement is on the rise, esp. after 9/11 rise, esp. after 9/11 Companies need to Companies need to strictly adhere to changing strictly adhere to changing regulations such as ITAR regulations such as ITAR and EAR or risk costly fines and EAR or risk costly fines Security initiatives Security initiatives requiring more internal requiring more internal control, record keeping and control, record keeping and audit trail audit trail Green supply chain as Green supply chain as competitive advantage competitive advantage Corporations need to Corporations need to comply with environment comply with environment laws and regulation such laws and regulation such as RoHS and REACH as RoHS and REACH Mandate of Clean Air Act Mandate of Clean Air Act Streamline environmental Streamline environmental reporting reporting Health care risk Health care risk assessment and prevention assessment and prevention Worker safety and Worker safety and hazardous materials need hazardous materials need to be documented and to be documented and identified identified
GRC Solution Overview Governance Risk Risk and and Compliance Financial Financial Compliance Compliance Trade Trade Environment Environment Regulations Regulations GRC GRC Access Access Control Control Suite Suite GRC GRC Global Global Trade Trade Services Services EH&S EH&S Environmental Compliance Environmental Compliance (EC) (EC) Compliance for Products Compliance for Products (CfP) (CfP) GRC Process Controls GRC Process Controls GRC GRC Risk Risk
SAP GRC Access Control Sustainable prevention of segregation of duties violations Minimal Time To Compliance Continuous Access Effective Oversight and Audit (Get Clean) (Stay Clean) (Stay in Control) Risk Identification and Remediation Enterprise Role Compliant User Provisioning Superuser Privilege Periodic Access Review and Audit Rapid, cost-effective and comprehensive initial clean-up Enforce SoD compliance at design time Prevent SoD violations at run time Close #1 audit issue with temporary emergency access Focus on remaining challenges during recurring audits Risk analysis, remediation and prevention services Cross-enterprise library of best practice segregation of duties rules
SAP GRC Risk Risk-adjusted management of enterprise performance Establish risk appetite and thresholds Collaborate and aggregate across the enterprise Balance cost of risk avoidance and opportunity Actionable rolebased dashboards and alerts SAP GRC Risk Balance business opportunities with financial, legal, and operational exposure to Balance business minimize opportunities the market penalties with financial, from legal, high-impact and operational events exposure to minimize the market penalties from high-impact events Risk Planning Risk Identification and Analysis Risk Response Risk Monitoring The framework for an integrated approach to ERM
SAP GRC Global Trade Services Solving global trade challenges Avoid delays at borders to ensure fast delivery to customers Expedite customs clearance to reduce costly buffer stock Make the most of international trade agreements Take advantage of export refunds SAP GRC Global Trade Services Ensure full regulatory compliance, expedite customs clearance, mitigate financial risk of global transactions, take full advantage of international trade agreements Export Import Trade Preference Restitution
SAP GRC EH&S and Environmental Compliance Solving environmental, health, safety challenges Cross-Industry Industry Specific Occupational Health Industrial Hygiene and Safety Hazardous Substance Product Safety Dangerous Goods Waste Air, Soil, Water Waste Product Compliance Chemical Mgmt SAP Environmental Compliance TechniData Compliance for Products CfP SAP REACH Compliance SAP EH&S Comprehensive and complete business solution for environment, health and safety management Applications for EH&S Compliance
Manage With Confidence Over 2200 customers worldwide rely on SAP Solutions for GRC Mitigate horizontal risks with SAP Global Trade Services and Virsa Access Enforcer for SAP Extended core processes with GRC; over 1 M compliance screenings/month Reduce compliance costs with Virsa Compliance Calibrator Eliminated 4,800 Staff Hours annually; audit costs 23% below norm Effectively manage increasing trade regulations with SAP Global Trade Services Automated 99.9% of export processes; Reduced headcount (450 14) Grow and stay compliant with multiple regulatory changes using SAP Global Trade Services Reduced cycle times (5 2 days) Improve occupational health with SAP Environment Health & Safety Incident numbers and cost down; replaced 11 legacy systems
SAP Global Trade Services
What is SAP Global Trade Services (SAP GTS)? SAP Global Trade Services manages all complexities of international trade including full regulatory compliance, interactions with customs and management of risk while trading on a global basis. It consists of separate modular components that enable companies to improve their supply chain and comply with international regulations. Export Import Trade Preference Restitution More than Export Control Exports SAP GTS More than Import Control Imports
Comprehensive Support For All Global Trade Activities SAP Global Trade Services Export Import Trade Preference Restitution Ensure full regulatory export compliance, generate and file customs documents, mitigate risk Ensure full regulatory import compliance, expedite customs clearance, mitigate risk Make the most of international trade agreements Take advantage of export refunds
SAP Global Trade Services (SAP GTS) Driving Efficient Cross-Border Trade Logistics/ Trade Team Import/ Export Officer IT Team Legal/ SOX Compliance Team Increased Productivity and Business Insight SAP Global Trade Services Adaptable Business Processes Based on Flexible Technology Platform Export Import SAP NetWeaver Trade Preference Restitution Integrate Systems, Data and Business Partners ERP Applications Data Business Partners SCM/ SRM CRM Legacy HTS ECCN, etc Duty Rates SPL Data Rules Of Origin Customer & Supplier Banks Freight Forwarder Customs Agencies
Tight Integration With Logistics Outbound and Inbound Processes ERP System Export Process Product & Business Master Data (Customer) Sales Order Delivery (Pro-forma) Invoice SAP GTS Product Classification (HTS, ECCN, Schedule B, ) Export/ Import Compliance Check ITAR/EAR License Det Letter of Credit (L/C) Check Export/ Import Compliance Check Bonded Warehouse Duty Calculation Customs Communication Export/ Import Document Printing L/C Compliant Printing ERP System Import Process Product & Business Master Data (Supplier) Purchase Order Shipping Notification Goods Receipt
SAP Export Ensures Trade Compliance Across Borders SAP Export Key Capabilities Sanctioned Party List Screening Screen business partners Screen documents at every step (orderto-cash and procure-to-pay process Comprehensive documentation Integration with Logistics, HR, Financial Export/ Import Control Manage export and import licenses (incl. Nested Licenses) Manage TAA and MLAs Automated assignment of licenses to a specific business transaction Ability to Interface with DDTC (D-Trade) Web Portal access to License Applications & Amendments (DSP- 5,61,73,85,119) Track quantity and value depreciation Content provider for USML (partner solution) Embargo Check Check for potential embargo situations SAP Import SAP Trade Preference Benefits Avoid costly fines and penalties through facilitating tighter national security Shorter delivery times through automated trade compliance processes Improve worker productivity via moving to management-by-exceptions Secure your corporate brand equity by avoiding negative press Be prepared for legal audits by having all required documentation at hand
ITAR Compliance with SAP GTS SAP GTS helps you manage ITAR Requirements across your enterprise Product Classification Assign the correct USML numbers to your products Export License Determination and A single, central location for end-to-end license management Embargo Check Automatic screening of destination country to identify potential ITAR issues Sanctioned Party List Screening Screen business partner, employees and applications against official sanctioned party lists Government Communication Certified support for electronic communication with the US Government Auditing and Record Keeping Maintain a complete audit trail to show authorities
SAP GTS Has Significant Market Momentum SAP GTS is the leader in global trade management space Over 450 Customers in 20 countries, including business world's best-known brands Business process knowledge and vast experience in 25 industries
Conclusion SAP GTS helps you reduce RISKS, TIME and COSTS Accelerate Cross-border Transactions Expedite customs clearance Accelerate delivery times Increase Efficiency Automated, standardized processes Tight integration into logistics processes $ Reduce Risk of Non-Compliance Avoid costly fines and penalties Complete and accurate audit trail Reduce TCO One central global trade solution Reduced software and hardware costs Reduce RISKS, TIME and COSTS
Industry Value Networks SAP s unique industry ecosystem initiative Technology Vendors Supporting Technology SAP IVN Lead & Enabler Customers Innovation Needs & Solution Validation ISVs Complementary Solutions System Integrators Industry Services & Solutions INDUSTRY ecosystems bringing together leading customers, partners & SAP Creating VALUE by focusing on priority industry needs & opportunities With strong NETWORK collaboration, combined expertise, resources & solutions
Thank you! Paul Pessutti Director, Strategic Applications SAP GRC paul.pessutti@sap.com +1 (650) 283-8354 Thank you! For further information, please visit: www.sap.com/grc
Copyright 2007 SAP AG. All Rights Reserved No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. Microsoft, Windows, Excel, Outlook, and PowerPoint are registered trademarks of Microsoft Corporation. IBM, DB2, DB2 Universal Database, OS/2, Parallel Sysplex, MVS/ESA, AIX, S/390, AS/400, OS/390, OS/400, iseries, pseries, xseries, zseries, System i, System i5, System p, System p5, System x, System z, System z9, z/os, AFP, Intelligent Miner, WebSphere, Netfinity, Tivoli, Informix, i5/os, POWER, POWER5, POWER5+, OpenPower and PowerPC are trademarks or registered trademarks of IBM Corporation. Adobe, the Adobe logo, Acrobat, PostScript, and Reader are either trademarks or registered trademarks of Adobe Systems Incorporated in the United States and/or other countries. Oracle is a registered trademark of Oracle Corporation. UNIX, X/Open, OSF/1, and Motif are registered trademarks of the Open Group. Citrix, ICA, Program Neighborhood, MetaFrame, WinFrame, VideoFrame, and MultiWin are trademarks or registered trademarks of Citrix Systems, Inc. HTML, XML, XHTML and W3C are trademarks or registered trademarks of W3C, World Wide Web Consortium, Massachusetts Institute of Technology. Java is a registered trademark of Sun Microsystems, Inc. JavaScript is a registered trademark of Sun Microsystems, Inc., used under license for technology invented and implemented by Netscape. MaxDB is a trademark of MySQL AB, Sweden. SAP, R/3, mysap, mysap.com, xapps, xapp, SAP NetWeaver, and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and in several other countries all over the world. All other product and service names mentioned are the trademarks of their respective companies. Data contained in this document serves informational purposes only. National product specifications may vary. The information in this document is proprietary to SAP. No part of this document may be reproduced, copied, or transmitted in any form or for any purpose without the express prior written permission of SAP AG. This document is a preliminary version and not subject to your license agreement or any other agreement with SAP. This document contains only intended strategies, developments, and functionalities of the SAP product and is not intended to be binding upon SAP to any particular course of business, product strategy, and/or development. Please note that this document is subject to change and may be changed by SAP at any time without notice. SAP assumes no responsibility for errors or omissions in this document. SAP does not warrant the accuracy or completeness of the information, text, graphics, links, or other items contained within this material. This document is provided without a warranty of any kind, either express or implied, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, or non-infringement. SAP shall have no liability for damages of any kind including without limitation direct, special, indirect, or consequential damages that may result from the use of these materials. This limitation shall not apply in cases of intent or gross negligence. The statutory liability for personal injury and defective products is not affected. SAP has no control over the information that you may access through the use of hot links contained in these materials and does not endorse your use of third-party Web pages nor provide any warranty whatsoever relating to third-party Web pages.