TrustRadius: an HG Insights company

SAP Process Control

Score9 out of 10

85 Reviews and Ratings

What is SAP Process Control?

SAP Process Control Simplifies uses continuous control monitoring, and streamlined testing, and reduces risk with real-time insight into control status and key issues. It can be deployed on premise or in the cloud.

Categories & Use Cases

Top Performing Features

  • Common repository of GRC items

    A common repository linking all GRC elements such as policies, risks, regulations, etc.) to give a 360 degree view

    Category average: 7.8

  • GRC policy management

    Support for policy lifestyle changes including creation, approval, communication etc.

    Category average: 7.7

  • Risk management

    Risk management capabilities including alert engine to warn of trending risk exposure and risk visualizations like heat maps, dashboards, etc.

    Category average: 7.4

Areas for Improvement

  • Incident management

    System captures risk-related incidents, including cause and result

    Category average: 7.8

  • Integration with Corporate Performance Management (CPM) systems

    Ability to integrate with external CPM software

    Category average: 7

SAP Process Control at a glance

Use Cases and Deployment Scope

We are using SAP Process Control as the backbone of our internal control system. It helped us to get rid of offline files, established a single source of truth, and helped us to implement a workflow based way of working. With the possibilities that SAP Process Control offers, we managed to mature our way of working as well as our internal control system.

Pros

  • Workflows - The workflows of SAP Process Control are extremely helpful
  • Reporting - Standard reports as well as the connection to SAP AC is very helpful
  • Continuous Control Monitoring is the way to go in ICS Topics in the future.
  • Handling of users - Assignment and Replacements
  • Spot Checks - Helpful workflows and setup

Cons

  • Connection to SAP AC
  • Easier workflows for remediation actions
  • Configuration of workflows - e.g. email templates for workflows
  • Survey design

Return on Investment

  • Better maturity of the ICS System
  • More Awareness on ICS Topics
  • More Assurance for the Management

Alternatives Considered

ARIS, ServiceNow Governance, Risk and and Compliance

Other Software Used

SAP Access Control, SAP Business Warehouse, SAP Master Data Governance

SAP Process Control helps us have more reliance on automatic monitoring of standard it controls

Use Cases and Deployment Scope

The product is useful for doing a lot of automation to monitor risks and to save time on testing of controls. The product has a lot of adoption to happen to check on more controls, which can help every customer to help on monitoring the risks and monitor mitigation without manual monitoring involved.

Pros

  • Monitoring IT controls
  • Monitoring the mitigations applied against risks defined in systems
  • Automatic monitoring of many IT and business controls will help save time and money for internal auditors and also assert more confidence in controls defined in the landscape

Cons

  • Default delivery of controls could be done by SAP on some basic controls like client openings, password controls, etc
  • The messaging or customization of messages in different workflows is limited, which could be introduced to enhance the product
  • SAP Process control does not have the capability for cloud product monitoring which is required with more SAP cloud products available right now

Return on Investment

  • Significant control on risks
  • Significant savings on audit testing can be achieved
  • Automation of risk management has a lot of audit standardization and confidence in compliance
  • Reliability of automated controls reduces time vested in testing the standard controls

SAP Process Control automates compliance initiatives

Use Cases and Deployment Scope

SAP Process Control helps to manage the end to end SOX compliance process and assist with monitoring of automated and configurable controls in the SAP application environment. The SOX compliance process includes a inventory of the SOX controls, performance of controls, test of effectiveness of the controls, and reporting on key gaps and issues with the control testing process.

Pros

  • Native connection to SAP applications
  • Automated monitoring process of SAP applications
  • Workflow capabilities for control testing

Cons

  • Integrated attachments functionality (i.e., edit Word/Excel documents within SAP PC, rather than having to download the files locally)
  • More flexible dashboarding capabilities
  • Better out of the box reporting
  • No out of the box content for Controls, Regulations

Return on Investment

  • Automated alerts for controls issues
  • Workflow capabilities; however, there's natively only 2 levels of review. More layers would be beneficial.

Alternatives Considered

AuditBoard, ServiceNow Governance, Risk and and Compliance