SAP Risk and Controls – System reliability and integrity to drive business performance

Avoid disruption, increase efficiency, and manage risk effectively in your SAP landscape

Focused on the day-to-day concerns of the business, management often feels too busy to ask if they’re getting all they can from their SAP investment. Companies will invest millions in an enterprise solution that’s supposed to streamline processes, introduce efficiencies, and simplify reporting. Then, after the dust settles, the same leaders are wondering what they got for the (substantial) money. Why are there still so many manual functions? Why is information no more reliable than before? Why are there costly disruptions and audit findings?

We help maximize the investment in SAP to drive system integrity and establish the trust you need to successfully operate. PwC helps you evaluate your SAP landscape for the future to:

  • Secure the system appropriately and establish strong governance to avoid costly disruptions or audit issues
  • Challenge the current processes and invest in moving away from manual processes
  • Identify the key hurdles to a sustainable process
  • Rationalize the number of controls and maximize automation, using our proprietary analytic engine to identify opportunities for SAP automated controls
  • Identify opportunities for trade policy consulting, compliance & risk mitigation, and strategic business planning
  • Put proactive control monitoring routines in place as a managed service, leveraging our comprehensive, automation-enabled approach to control monitoring
  • Improve control operations & testing, leveraging the speed of HANA for audit transformation with our award-winning Intelligent Testing platform, Enterprise Control
1:45
Video Player is loading.
Current Time 0:00
Loaded: 0%
Duration 0:00

Playback of this video is not currently available

Intelligent Controls for SAP S/4HANA

Getting more value from your SAP applications

PwC has had a group focused exclusively on SAP security, controls, GRC, and cybersecurity solutions since the mid-1990s. Since 2014, PwC has positioned itself as a leading S/4HANA partner. We are focused on driving operational efficiency, system protection, and compliance excellence through integrating risk, process and technology platforms. As an SAP Platinum Partner, we bring our approach, experience and proprietary accelerators to help our clients address the security, operational and compliance challenges throughout the S/4HANA business transformation journey.

SAP Platinum Partner logo

Security

Designing and building simple, scalable and sustainable access management roles to secure your data in your SAP applications.

Challenges defining security and governance, risk, and compliance strategies and a lack of guiding principles during the implementation cause pain points for end users and decrease productivity during the Sustain phase. Whether it is during the implementation, or post go-live, we at PwC help our clients with:

  • Role design, risk monitoring, controls & access management for Fiori & HANA database, maximizing SAP GRC technology
  • Automating provisioning via workflows and governing access in a straight-forward process that supports compliance
  • Maximizing SAP security role design to reduce overhead maintenance and simplify access

With the introduction of S/4HANA, traditional application level security concepts remain in place; however, additional complexities are introduced via the need for HANA database level security for end users, security around new interface options such as Fiori, security controls around changing business processes, and new vectors for cyber security risks.

SAP Controls & Monitoring

Enterprise Control

Improving control operations & testing, leveraging the speed of HANA for audit transformation.

Analytic capabilities are changing the way audit evaluates the effectiveness of controls. Our Enterprise Control platform is infused with trusted PwC expertise to automate the operation and testing of SAP controls. With Enterprise Control, our clients can:

  • Use PwC’s analytic engine to identify opportunities for SAP automated controls.
  • Automate the extraction of SAP data and introduce Control Testing Automation.
  • Use a centralized portal to maintain compliance programs, control monitoring and test plans.
  • Gain actionable responses to analytics results, providing precise insights into business risks with pre-built SAP specific control and transaction analytics.
  • PwC’s Proprietary cross system analytics solutions that helps you assess risks within your enterprise system data. With a reporting portal and the ability to workflow results, this monitoring platform provides one solution to support a data-driven approach to manage business process risks and controls.
  • PwC’s Transaction Outliers solution powered by Enterprise Control analyzes every transaction within a business process, highlighting those transactions that violate business process rules.

Learn more

Intelligent Controls, powered by the Enterprise Control platform

Building confidence in your enterprise applications by unlocking a holistic, universal view of risk through intelligent control design, execution and automated testing.

PwC’s Intelligent Controls Diagnostic ingests current state control frameworks, extracts data directly from SAP and analyzes it against a singular benchmark—one that’s been thoughtfully and expertly developed by PwC specialists with deep knowledge of regulation, enterprise tech, and automation. It quickly and accurately diagnoses where an enterprise’s risk stands, opportunities to automate and optimize controls, and a concrete estimate of ROI.

PwC’s Intelligent Controls Diagnostic is about lowering the overall cost of compliance by not only reducing control count, but by automating manual control processes and automating the test of controls.

Learn more

Application Security & Controls Monitoring (ASCM) Managed Services

Performing the specialized activities of monitoring security, controls, and transactions for business applications to reduce compliance costs.

Companies are investing in a state-of-the-art S/4 system with a leading practice security and control design.  Once they are live with this solution, this investment needs to be protected and maintained through proactive control monitoring routines. ASCM is a comprehensive, automation-enabled approach to control monitoring that increases confidence in their S/4 system.

The growing focus from audit firms and regulators around SAP-run control environments demands a robust understanding of the complexities of key configurations, security, and transactions. PwC has invested heavily in the content driving this solution. Our content was built leveraging over 20 years of experience and thousands of SAP controls projects, including external audits.

Combining PwC’s extensive leading practice SAP security and control content; state-of-the-art Enterprise Control technology; and our Acceleration Center-enabled managed services operating model to provide clients with the information they need to know, when they need to know it.

Learn more

Contact us

Elizabeth McNichol

Principal, Cyber, Risk and Regulatory, PwC US

Scott Osterman

Partner, Cyber, Risk and Regulatory, PwC US

Follow us