BWise GRC Implementation Review
Use Cases and Deployment Scope
BWise is used as a GRC platform to manage multiple compliance initiatives for SOX, IT compliance, PCI compliance, Procurement compliance, Internal Audit, and Management Self-testing.
BWise is integrated with TeamMate audit tracking, for internal audit testing and annual compliance testing.
BWise is used for testing across the enterprise, giving management a view into the control effectiveness, across the company, and across compliance initiatives.
Pros
- Bwise is very customizable to accommodate multiple compliance initiatives, across the enterprise.
- Integration with TeamMate, made tracking audit testing and results easy to stay on top of.
- Being able to map controls, and test once, and report control effectiveness for multiple initiatives was important.
Cons
- Integration with SAP for continuous control monitoring.
- Control mapping to standards: ISO; COSO; COBIT; HIPAA; SP800_53 (NIST); FedRAMP; PCI_DSS; BITS; GAAP; AICPA; BSI; CCM; COPPA; CSA
- Surveys.
Likelihood to Recommend
Well suited for general compliance, multiple initiatives, and integration with TeamMate.
SAP GRC Process control may be better suited for an SAP environment.
Oracle GRC may be better suited for an Oracle environment.
Overall, BWise is a very cost effective, and flexible solution.