Applications for Governance, Risk and Compliance (GRC) and Applications for Performance Management Proactively identify, analyze, respond to, and monitor risk across your area of responsibility.
http://www.sap.com/solutions/grc/riskmanagement
Business Processes |
Risk Planning![]() |
Risk scenarios can be defined which include several risks for
“what-if” planning. By changing the assumptions which drive the
analysis of the risks, you can determine the aggregate impact of
the different risk scenario.
|
|||||||||||
Risk Identification and Analysis![]() |
For each organisation/ critical infrastructure/ key asset, key activities are documented and the key risks to those activities are documented. Activities are described in terms of customizable categories, assumptions, and owner. An assessment frequency is set for each activity. Risks are described in terms of customizable categories, cause and consequence, indicator, owner, and comment. Risks are evaluated in terms of probability, impact and total loss. Both qualitative and quantitative methods are possible. The risk assessment is done both before a response and after the response. Based on end user input, expected loss is calculated. |
|||||||||||
Risk Response![]() |
Multiple responses can be documented for a single risk. The
responses are characterized by customizable type, cost, owner, and
status. Multiple responses can be documented for a single risk.
|
|||||||||||
Risk Monitoring![]() |
Each grouping of risks needs to be updated at a certain point in
time, based on the priority of the activity and the decision of the
activity owner. Based on this timeframe being reached, a workflow
is triggered to the risk owner to update the analysis values.
Online reports highlighting the aggregated expected and total loss
for an activity or org unit are available.
|
|||||||||||
| ||||||||||||