SAP Financial Compliance Management
Vincent Doux
GRC, Cybersecurity and Data Protection Specialist, SAP Customer Solution Advisor (CSA) for Finance & Risks in EMEA
Quick Intro: SAP Financial Compliance Management and SAP S/4HANA
In March 2021, we proudly announced the availability of the first version of SAP Financial Compliance Management which is our brand new control solution in the cloud. The aspects of financial compliance are as numerous as they are varied, and knowing which ones are relevant for your organization can be challenging. SAP Financial Compliance Management provides all the tools needed to ensure that your organization adheres to local laws and regulations. From documenting the processes in place for your organization to setting up checks and controls, the solution enables you to fulfill all tasks necessary to ensuring financial compliance.
SAP Financial Compliance Management is built on SAP Business Technology Platform and provides end-to-end financial compliance. In the light of constantly rising efforts and cost regarding financial compliance, companies are looking for more more and more automation. With SAP Financial Compliance Management, you can establish a proactive risk management instead of just fixing after-the-fact issues. This way, the role of GRC is changing from a cost factor to a strategic differentiator allowing you to optimize your business.
With SAP Financial Compliance Management, compliance specialists can design controls and link them to existing organizational units and business processes, monitor the performance of controls and determine their effectiveness, they can document a regulatory framework of applicable laws and regulations and last but not least detect issues in the implementation of controls and create remediation plans.
Fig. 1: With SAP Financial Compliance Management, compliance managers can design controls and monitor their performance
By integrating SAP S/4HANA and SAP Financial Compliance Management, compliance managers define controls and procedures to monitor financial operation processes and detect anomalies when connected to the SAP S/4HANA system. As you are well aware, financial processes generate a multitude of documents every day. Aside from manual checking and review, the new scope item ‘Financial Operation Monitoring with SAP Financial Compliance’ (3KY) enables continuous monitoring of transaction information and detects activities that may cause financial loss. The results from these monitored processes provide insights for the financial process in a company. Please note that this scope item requires additional licensing.
More Information
Predefined Stories for SAP Financial Compliance Management in SAP Analytics Cloud
Over the course of the year, SAP Financial Compliance Management has been extended step by step and now with the 2021 release, we are proud to present two predefined analytical stories for SAP Financial Compliance Management in SAP Analytics Cloud.
Story for Run Results Data Analysis
This story provides compliance managers with compliance analyses by organizations, processes, and regulations. Moreover, it contains detailed analyses of manual procedures, procedures runs, as well as a breakdown of procedure runs over time.
Fig. 2: The story for SAP Financial Compliance Management with run results data provides compliance analyses by organizations, processes, and regulations
As an example, I will now dig a bit deeper into one of the underlying views: The?compliance analysis by processes: In the upper left corner of the view, you see the number of failed controls per processes. ‘Failed’ means that SAP Financial Compliance Management has executed a control via a work package and has found entries in the SAP S/4HANA which match our search criteria. So, for example, when we look at process ‘P2: Reimburse to Pay’, there are 3 controls which have been assigned to this process and have failed items.
In the upper right corner, you see the top-5 failed controls meaning the controls with the most failed items. Here, control ‘C5: Verify the Authenticity of General Ledger Accounts’ has had the highest number of failed items and is therefore top 1. At the bottom, you see the analysis by control risk level and by significance. Both is data, that you can use to specify your controls with SAP Financial Compliance Management.
As mentioned above, the run results data story consists of several other views. If you are interested in further information, check out?Video 1?below. It was recorded for SAP S/4HANA Cloud, but is equally valid for SAP S/4HANA.
Fig. 3: With the analytical story for run results data analysis for SAP Financial Compliance Management, compliance managers can analyze compliance by process
Analytical Story for Master Data Analysis
The second story is allows to analyze the maintenance of master data for SAP Financial Compliance Management. You can display the distribution of controls by certain criteria, such as regulations, you can see which controls owners have been assigned to which controls. You can find missing assignments in controls regarding organizations, process, regulations, control owners, control groups, and procedures. You can see which procedures haven been assigned to which controls and you can find orphaned data meaning existing objects which have not been used, assigned, or scheduled so far.
As an example here, I have picked the view regarding the distribution of controls. In the upper left corner, the pie chart shows how the controls are distributed by regulation. In this case, more than 38% of the controls are assigned to regulation R1. The second pie chart in the lower left corner shows the distribution by control group. Here, 50% of the controls are assigned to control group ‘Record-to-Report’. On the left-hand side of the screen, the heat map shows the distribution by organization and by processes. For example, the column ‘Unassigned’ immediately draws your attention to those controls where an organization has been assigned but no process.
Fig. 4: The predefined story for master data analysis allows to analyze the master data of controls and related objects
领英推荐
As an example here, I have picked the view regarding the distribution of controls. In the upper left corner, the pie chart shows how the controls are distributed by regulation. In this case, more than 38% of the controls are assigned to regulation R1. The second pie chart in the lower left corner shows the distribution by control group. Here, 50% of the controls are assigned to control group ‘Record-to-Report’. On the left-hand side of the screen, the heat map shows the distribution by organization and by processes. For example, the column ‘Unassigned’ immediately draws your attention to those controls where an organization has been assigned but no process.
Fig. 5: As of SAP S/4HANA 2021, compliance managers can analyze the distribution of their controls by regulation, control group, or organization and processes with SAP Financial Compliance Management.
As mentioned above, the story for master data analysis consists of several other views. If you are interested in a detailed system demo, check out?Video 1?below. It was recorded for SAP S/4HANA Cloud, but is equally valid for SAP S/4HANA.
Detailed System Demo of of Analytical Stories
If you are interested in a detailed system demo of the new SAC stories for SAP Financial Compliance Management in SAP Analytics Cloud, check out the following video. It was recorded for SAP S/4HANA Cloud, but is equally valid for SAP S/4HANA.
Best Practice Content for SAP S/4HANA
With SAP Financial Compliance Management, compliance managers benefit from more than 60 most commonly used, predefined controls which can be used out-of-the-box with SAP S/4HANA and S/4HANA Cloud. Thanks to this, you can check your SAP S/4HANA system for suspicious activities and detect, for example, suppliers with disabled duplicate invoice or overpaid purchase orders compared to goods receipt.
With SAP Financial Compliance Management, you can choose between leveraging these finance-related automated controls either out-of-the-box or you can use them as templates for your own customer-defined controls. The corresponding scope item for SAP S/4HANA Cloud is called ‘Financial Operation Monitoring with SAP Financial Compliance (3KY).
Fig. 6: The business content from SAP Financial Compliance Management for SAP S/4HANA provides more than 60 most-commonly used, predefined controls
Now, you might be wondering where you as a customer can find the best practice content of SAP Financial Compliance Management. Well, the answer is pretty easy: You will find it directly in your customer system in the apps ‘Manage Automated Procedures’ and ‘Manage Controls’ as draft versions which you can use
More Information
Control for Revenue Recognition
One very prominent example of the business content for SAP S/4HANA is the control for contract-based revenue recognition which allows you to automate the detection of compliance risks before their effects become material to financials and are identified by auditors. You can use the automated compliance rule to detect a critical deterioration of the actual selling prices compared to the standalone selling prices applied in accounting for the transactions. You can evaluate past transactions to assess whether a narrow range of observable selling prices exists and verify whether the correct standalone selling price is applied to the underlying product or service for the allocation of the transaction prices.
With SAP Financial Compliance Management, you can prioritize your work items for checking revenue issues and track findings and resolution for full auditability, increase overall reliability of financials and provide feedback to policy owners for common issues requiring clarification. In addition, you can utilize a platform to quickly analyze issues and extend the controls on a common framework for setting up detection rules, running automated controls, and remediating identified issues.
In order to achieve this, you can compare the transaction prices that were charged with the standalone selling price (SSP) range for variable time periods, e.g. the previous four quarters. You can validate SSP compliance for each group (e.g. performance obligation name in Revenue Accounting) and a percentage of transactions concentrated around the +/- corridor for the standard SSP price. In addition, you can check the SSP compliance to evaluate whether the correct SSP is applied to the underlying product/service for the allocation of the transaction prices in multiple element arrangements (MEAs).
More Information
SAP Cybersecurity Leader | Market Strategy, Compliance, Risk
3 年Great overview - thanks Vincent Doux