SAP - TINET - Tarragona Internet

(Ron) #1
The project staff is made up of contractors only.Make sure key
internal staff works on the project as well. Having only contractors
assigned to the project means that little knowledge transfer will take
place. Furthermore, contractors don’t have a relationship with the
business and won’t know the unique circumstances and challenges
your company faces.
No authority.Project leaders are given little decision-making authority
and are simply told to just keep doing things the way we’ve always done
them. Successful GRC implementations require lots of input as well as
latitude to make important changes.

Define GRC Roles and Responsibilities .....................................................


A successful GRC implementation requires broad participation. So the first
question you may hear is “What do I have to do?” Table 16-1 contains some
answers, depending on who asks the question.

Table 16-1 GRC Roles and Responsibilities


Role Their Responsibilities

Business process owners and Identify risks and approve risks for
business analysts monitoring

Approve user role assignments

Design alternative controls for
mitigating risks

Communicate access assignments
or role changes to users

Architect business processes

Identify configuration alternatives

Conduct gap analysis on current
processes

Explain the key control integration
into the processes

Senior officers Arbitrate conflicts between
business areas

300 Part V: The Part of Tens

Free download pdf