79
Copyright © 2007 Design Processes • Supervise Realization • Control Changes • Enforce Compliance Process-Driven Risk Management, Governance and Compliance Solution Business Process Realization The ProcessGene™ GRC Suite Business Process Realization Solutions for Multi-Subsidiary Enterprises

ProcessGene GRC Software Suite

Embed Size (px)

DESCRIPTION

ProcessGene develops forward-thinking GRC software solutions, designed to serve multi-subsidiary organizations. The company has been acknowledged as a market leader and innovator by the most important analyst firms. Businesses and governments worldwide use ProcessGene solutions to manage and control risks, assure compliance to policies and regulations, manage corporate governance programs, and perform internal audits. ProcessGene’s Multi-Org technology enables synchronized management of several business process models (e.g per subsidiary), all linked to a centrally controlled, global business process baseline. ProcessGene also offers a full range of Multi-Org Business Process Management (BPM) solutions. For more information, visit www.processgene.com. http://www.processgene.com//index.php?pageIndex=grc-solutions

Citation preview

Page 1: ProcessGene GRC Software Suite

Copyright © 2007

Design Processes • Supervise Realization • Control Changes • Enforce Compliance

Process-Driven

Risk Management, Governance

and Compliance Solution

B u s i n e s s P r o c e s s R e a l i z a t i o n

The ProcessGene™ GRC Suite Business Process Realization Solutions

for Multi-Subsidiary Enterprises

Page 3: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 4 of 85

An end to end GRC software suite,

designed for multi-subsidiary enterprises

• The first integrated BPM/GRC suite in SaaS

• The only “Multi-Org” BPM/GRC solution-

designed for multi-subsidiary enterprises

ProcessGene’s Offering

Page 4: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 5 of 85

ProcessGene GRC Solutions

Business Process

Management Engine

Connectivity to

ERP systems

Multi-Org

Mechanism

Search and

Reports Module

GRC Diagnostics

and Dashboards

Task and Workflow

Platform

Graphics

engine for

Diagrams

Collaboration

Mechanism

End-to-end GRC enablers

SaaS Platform

Internal

Audit

IT GRC

Regulatory

Compliance

Risk

Management

Corporate

Governance

End-to-end GRC enablers

Page 5: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 7 of 85

Risk Management

• Identify, evaluate and prioritize organizational risks

• Relate risks to relevant business processes, systems

and organizations

• Mitigate and control the risks

• Track and diagnose progress of the risk management

program

• Link KRIs to processes or risks

• Record and categorize loss events

• Manage opportunities vs. risks

• Global and optimized risk vs. return management

• Business processes that involve high risks are easily

monitored and diagnosed

Page 6: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 8 of 85

• Designed for multi-subsidiary, global

organizations

• Very fast implementation

• Full automation

• Direct connectivity to ERP systems

• Leaders in cloud provisioning

• Multiple frameworks:

• Unlimited amount of free “view” users

Benefits and Differentiation of the

ProcessGene™ GRC Solution

Page 7: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 9 of 85

Regulatory Compliance

• Support a wide array of compliance programs covering

USA and EMEA regulations

• Specialized functionality & repositories for specific

compliance programs

• Sample regulations: SOx, FDA, FERC, NERC, FAA,

OMB A-123, EH&S, HACCP, ISO 22000, PCI, BSA,

Patriot Act, GLBA, KYC, AML, Basel II, MaRisk, ISOx-

Goshen, SAS70, eTOM, PCI-DSS, ISO 27002, NIST

• End to end solution, covering the entire regulatory

compliance cycle

• A common framework to comply with the on-growing

regulatory scope enables to reduce compliance costs

Page 8: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 10 of 85

IT GRC

• Measure and mitigate IT risks by implementing controls that

ensure the security and integrity of data, systems, networks

and IT facilities

• Ensure compliance with a set of IT regulations governing data

retention, privacy, confidential information, change

management, vendor information and disaster recovery

• Based on leading control frameworks such as Cobit, ISO

27002, NIST, ITIL

• Automation effectively reduces the cost of enforcement, while

providing improved and quantifiable compliance results

• Direct connectivity to enterprise software systems automates

and improves the effectiveness of IT compliance enforcement

• Easy access to objective evidence for compliance

enforcement

Page 9: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 11 of 85

Internal Controls

• Document, test, sign-off and monitor the organizational

controls

• Automated workflows simplify follow up on testing, sign-

off and deficiency remediation

• Collected evidence is documented electronically, with full

audit trail

• Automation reduces costs and prevents errors that are

caused by manual, non validated activities

• A control is tested once and then re-used for several

compliance purposes and goes through several types of

audits

Page 10: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 12 of 85

Corporate Governance

• Manage a dynamic set of processes, policies and

procedures related to reliability, integrity and compliance

with laws and regulations

• Deploy a workflow of automated approvals to ensure that

governance is communicated and enforced

• Verify, through surveys and enterprise wide

acknowledgment processes, that governance is

disseminated and enacted

• Enable a clear and traceable accountability mechanism

to ensure adoption of corporate governance principles

• Comply with required legal regulations

Page 11: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 16 of 85

ProcessGene™ GRC: Five Roles,

Seven Responsibilities

Role Responsibility

GRC Manager

Control Owners

Internal Testers

External Auditor

Approvers

Document Business Processes

Risks, Controls, Test Plans

Manage deficiency

remediation

Sign-Off Business

Processes

Conduct tests over Controls.

Report test results

Review efficiency of Controls

based on test results Verify deficiency

remediation

Execute Controls and document

execution evidence

Page 12: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 17 of 85

Login to the USA environment

Page 13: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 18 of 85

Page 14: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 19 of 85

Page 15: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 20 of 85

Page 16: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 21 of 85

Page 17: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 22 of 85

Easily define and edit the process description and its properties

Page 18: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 23 of 85

Easily edit the process Diagram

Page 19: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 24 of 85

ERP Screens

Description ERP transaction/ Automatic GRC test

Execute the automatic test or “jump” directly to an exact location at the ERP system

Page 20: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 25 of 85

The SAP transaction is automatically opened

Direct connectivity to the ProcessGene application

Any SAP Screen

Page 21: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 26 of 85

The Oracle screen is automatically opened

Direct connectivity to the ProcessGene application

Page 22: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 27 of 85

Relate Risks and Controls to the Process

Define the list of related Risks

Jump to Controls management

Page 23: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 28 of 85

A selected Risk’s properties

Raw and residual levels

Related opportunities

The Risk’s description

Page 24: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 29 of 85

A selected Risk’s diagnostics

Page 25: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 30 of 85

Historical cost events

Page 26: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 31 of 85

The Risk’s audit plan and audit execution data

The Risk’s audit plan, audit schedule and audit results, including the documentation of historical results and the management of deficiency remediation

Page 27: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 32 of 85

Tasks related to the modeling and management of the Risk

Page 28: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 33 of 85

Documents related to the modeling and management of the Risk

Page 29: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 34 of 85

Define the list of related Controls

Relate Risks and Controls to the Process

Page 30: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 35 of 85

A selected Control’s properties

Press to edit the selected Control’s properties

Assign a Control owner

Determine execution frequency

Page 31: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 36 of 85

All fields are editable in the Control’s edit form

Page 32: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 37 of 85

Page 33: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 38 of 85

Page 34: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 39 of 85

The Control’s test plan and test execution data

The Control’s test plan

Define the Test and the criteria for the Test’s success/failure

Page 35: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 40 of 85

The Control’s test schedule

Assigned tester(s) Scheduling data

Page 36: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 41 of 85

Assign testers for the Control

Edit the Control’s Test schedule

Page 37: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 42 of 85

Select a tester

Save

Page 38: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 43 of 85

Define the test’s schedule

A tester was Assigned

Page 39: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 44 of 85

Scheduling data

Page 40: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 45 of 85

A tester was assigned A schedule was defined

Page 41: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 46 of 85

ProcessGene™ GRC: Five Roles,

Seven Responsibilities

Role Responsibility

GRC Manager

Control Owners

Internal Testers

External Auditor

Approvers

Document Business Processes

Risks, Controls, Test Plans

Manage deficiency

remediation

Sign-Off Business

Processes

Conduct tests over Controls.

Report test results

Review efficiency of Controls

based on test results Verify deficiency

remediation

Execute Controls and document

execution evidence

Page 42: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 47 of 85

Page 43: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 48 of 85

Page 44: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 49 of 85

Page 45: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 50 of 85

Page 46: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 51 of 85

Page 47: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 52 of 85

Page 48: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 53 of 85

ProcessGene™ GRC: Five Roles,

Seven Responsibilities

Role Responsibility

GRC Manager

Control Owners

Internal Testers

External Auditor

Approvers

Document Business Processes

Risks, Controls, Test Plans

Manage deficiency

remediation

Sign-Off Business

Processes

Conduct tests over Controls.

Report test results

Review efficiency of Controls

based on test results Verify deficiency

remediation

Execute Controls and document

execution evidence

Page 49: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 54 of 85

An automatic email from the control’s testing reminder

Email notifications are optional

Page 50: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 55 of 85

Elizabeth Martin’s Personal task list

Open the Control’s test task to execute it

Page 51: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 56 of 85

Read the Control’s test plan and execute it accordingly

Page 52: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 57 of 85

Report test results.

All results are documented in the system

and history is saved.

Page 53: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 58 of 85

The Control’s test results

are documented in the system

Page 54: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 59 of 85

The Control’s test result history

Page 55: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 60 of 85

Defining, assigning and scheduling the required deficiency remediation tasks

Page 56: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 62 of 85

ProcessGene™ GRC: Five Roles,

Seven Responsibilities

Role Responsibility

GRC Manager

Control Owners

Internal Testers

External Auditor

Approvers

Document Business Processes

Risks, Controls, Test Plans

Manage deficiency

remediation

Sign-Off Business

Processes

Conduct tests over Controls.

Report test results

Review efficiency of Controls

based on test results Verify deficiency

remediation

Execute Controls and document

execution evidence

Page 57: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 63 of 85

View the status of Controls in the entire organization

Page 58: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 64 of 85

A distribution of the Controls’ test results

Page 59: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 65 of 85

A distribution of the key Controls’ test results

Direct access to grouped Controls (e.g to the ineffective group)

Page 60: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 66 of 85

A distribution of the Raw Risk weight in the organization

The average Raw Risk level and Residual Risk level vs. the average Risk tolerance in the organization

Page 61: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 67 of 85

The average controlled vs. residual risk levels in the organization

Page 62: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 68 of 85

The average controlled vs. residual risk levels in the organization – distributed per category

Page 63: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 69 of 85

All tasks in the organization can be viewed, monitored and managed from this area

Jump to the end

Page 64: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 70 of 85

Sign-off Processes

Define Sign-off tasks per process

Page 65: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 71 of 85

View a Sign-off task details

Page 66: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 72 of 85

Edit a Sign-off task details

Select the required signing statement

Assign user(s)

Page 67: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 73 of 85

Select a tester

Save

Page 68: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 74 of 85

Edit a Sign-off task details

Define the task’s schedule

A user was Assigned

Page 69: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 75 of 85

Scheduling data

Page 70: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 76 of 85

The Sign-off task is defined

Page 71: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 78 of 85

ProcessGene™ GRC: Five Roles,

Seven Responsibilities

Role Responsibility

GRC Manager

Control Owners

Internal Testers

External Auditor

Approvers

Document Business Processes

Risks, Controls, Test Plans

Manage deficiency

remediation

Sign-Off Business

Processes

Conduct tests over Controls.

Report test results

Review efficiency of Controls

based on test results Verify deficiency

remediation

Execute Controls and document

execution evidence

Page 72: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 79 of 85

An automatic email from the Process’s Sign-off reminder

Page 73: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 80 of 85

Michael Chang’s Personal tasks area

Michael Chang’s Sign-off task

Page 74: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 81 of 85

Sign-off task details

Required action: Approve now

Approval declaration

Page 75: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 82 of 85

Confirm the Sign-off declaration

Page 76: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 83 of 85

The Sign-off declaration is documented in the system

Page 77: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 84 of 85

All historical Sign-offs for this process

Page 78: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 85 of 85

A gauge indicating the current organizational Sign-off status

Page 79: ProcessGene GRC Software Suite

Copyright © 2007 Business Process Realization Copyright © 2011 Slide 87 of 85

Thank You!

ProcessGene Ltd.

For additional information:

www.processgene.com