Home > SAP software/management News > SAP denies Gartner report that its GRC solutions are incomplete
SAP software/management News:
EMAIL THIS

SAP denies Gartner report that its GRC solutions are incomplete

By Courtney Bjorlin, News Editor
29 May 2008 | SearchSAP.com

SAP news, tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

SAP reacted harshly to a report this week from Gartner that found SAP's governance, risk and compliance (GRC) software suite lacking.

Specifically, the Stamford, Conn.-based research firm said the GRC suite lacks an application that will provide the management functions needed to find areas that require remediation and provide reports that ensure compliance.

SAP needs something like Oracle's GRC Manager for internal auditors, compliance managers and executives to highlight areas of remediation and provide up-to-date documentation on what's going on, French Caldwell, research vice president with Gartner, said. He wrote the research note following SAP's recent Sapphire event. SAP also needs a common repository that can share data among risk management, compliance management, audit management and policy management, the report says.

"No vendor is going to be able to cover the entire corporate governance spectrum," Caldwell said. "But if you cannot prove it and report it, then you might as well not be doing it as far as an auditor is concerned."

SAP denounced the findings and recommendations.

"Where do you start?" said Jim Dunham, who is group president of GRC Solutions Management at SAP. "This was so far off, it's not even funny."

For more on SAP's governance, risk and compliance software
SAP adds risk components to compliance offerings

Compliance essentials: Building a technology toolbox

SAP says its GRC applications, five in all, are one step ahead of making sure companies are in compliance. What Caldwell is calling for in a separate application is already built into SAP's GRC solutions, Dunham said.

SAP views compliance from an automation and continuous policy management standpoint, Dunham said, so there's no need for extensive, physical reporting. Because problems are highlighted and corrected as they arise, there's no need for extensive documentation.

"The only way we saw you could [ensure compliance] is through some form of automation," Dunham said. "[Caldwell is] asking for the support, for a more intensive paper approach, more intensive audit management. We fundamentally have a completely different approach. It's almost like an easy button."

Some of SAP's biggest GRC customers agree.

"If you get into GRC as a whole, we're going to start seeing more of that. It's going to be about the integration," said Dale Timmons, managing director at UHY Advisors Tax and Business Consultants, a Houston-based business that uses SAP's Enterprise Risk Management module. "They're probably the closest to working at continuous compliance. SAP, I think, is way ahead of everybody else."

Lee Dittmar, principal of Deloitte Consulting LLP, agreed.

"We're moving away from discrete tools for specific compliance and risk domains," Dittmar said. "The whole topic of risk and compliance doesn't make sense to live a separate life from performance management. The systems that will enable efficient risk and compliance management may need to be part of an integrated solution. If you look discretely only at one product, you're missing the point."

In his note, Caldwell advises customers to look at other solutions for GRC management functionality – including Oracle's GRC Manager, OpenPages, Paisley and MetricStream.

"SAP needs to put urgency into fleshing out its GRC management capabilities to match its vision of being a leading GRC vendor across the spectrum of GRC markets, not just the segregation of duties and financial control markets," Caldwell wrote. "Until SAP does so, [enterprise] GRC (EGRC) platform buyers should look to Oracle and the many best-of-breed EGRC platform vendors."

Predictably, SAP doesn't think so.

"We're very clearly the market leader as it relates to this space," Dunham said, adding that SAP has added 700 net new customers since 2007.

SAP and Gartner do, however, seem to agree on one thing.

"There's a difference of opinion between SAP and Gartner on this," Caldwell said. "I think that's a healthy thing."



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


SAP Training & Employment
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2010, TechTarget | Read our Privacy Policy
SearchSAP.com is a search service provided by TechTarget and is completely
independent of and not affiliated with SAP AG.
  TechTarget - The IT Media ROI Experts