Skip to Content
author's profile photo
Former Member

Cost and Timeline of SAP GRC implementation


Can anyone give me an idea about the typical cost and timeline to implement SAP GRC? Let's say for 30000 user community?



Add comment
10|10000 characters needed characters exceeded

  • Follow
  • Get RSS Feed

1 Answer

  • author's profile photo
    Former Member
    Posted on Sep 27, 2010 at 02:02 PM


    depends how many system you will connect GRC to.



    Add comment
    10|10000 characters needed characters exceeded

    • Former Member


      I can see where you are coming from with the number of systems but that shouldn't be a major contributor should it? Having a global ruleset challenged by multiple users or by multiple systems can cause 'noise' but, then again you also get several authorisation consultants hopefully working together to find a common best set of rules. (As long as they aren't using the RAR by bunker mentality).

      Local rulesets for different SAP systems are part of the deliverables...

      Then you need to have an idea of how bad your authorisations are, has there been a controlled role owner process in place, what about locked and expired user controls, do you have multiple SAP_ALL/SAP_NEW users or super users who will be unwilling to give up their access.

      Are your roles in a fit state to undergo a remediation at role and then user level (granular or role based etc)

      One other thing to consider are your custom transactions - how many and how badly restricted/documented are they? This particular aspect can turn into a mini project of its own!

      As the saying goes - my tuppence worth! Hope it helps a bit.

      Kind regards