What were the costs of managing the risks and implementing a response
plan compared to the costs of the incident?
What was the nature of the loss? Was it a financial loss? An opportunity
loss?
What was the root cause? Is our product out of date or not suited for the
current market? Were our people (sales or support) unfriendly or
unhelpful?
What response strategies did we try and why didn’t they work? Maybe
they did work, but not as well as you hoped. In either case, you need to
know what went wrong where and how you can do better next time.
Incidents have much to teach you, and doing an analysis of what went wrong
is important to making more things go right in the future.
Automating the Risk Management Cycle ....................................................
So far in this chapter, we’ve talked about managing risks in a manual way. How-
ever, the process of monitoring risks can be automated as well by implement-
ing an enterprise risk management software application. For example, if you
enter a lead for a potential sale with a dollar value above a certain amount,
the enterprise risk management software could alert the key participants
about the risk, or even implement a workflow to send a survey to document
the key risk information regarding the deal. Once submitted, that survey
could be sent to the risk manager or to your manager, depending on how it
has been set up, and key risk indicators against this risk could be automati-
cally monitored. This implies a level of integration between the software you
use to track leads and your enterprise risk management software.
Taking the SAP Approach: SAP GRC Risk Management ............................
The SAP application that supports this enterprise approach to risk manage-
ment is called SAP GRC Risk Management. This application is integrated with
all other SAP applications, making it easy to raise alerts about key business
processes right from the software itself. Monitoring these risks is a key fea-
ture of SAP GRC Risk Management.
58 Part I: Governance, Risk, and Compliance Demystified