cancel
Showing results for 
Search instead for 
Did you mean: 

CUP Detour by Risk Id ??

Former Member
0 Kudos

Hello All,

My client requirement is to deroute CUP request to different risk owners based on risk ids. The custom field does not have the option to specify the risk id. Could you let me know wht is the possible option to detour based on Risk ids to respective Risk owners?

Regards,

Sudhakar S

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hello Kaushal & Simon,

Thanks for your response. My Client is on GRC5.3 & need CUP to be config to reroute to respective risk owners based on risk ids? Mitigation Controller / Approver would also suffice fot this purpose. All we need is the request to reroute to respective risk owners based on risk ids for approval.

Sudhakar S

Former Member
0 Kudos

Hi Sudhakar,

Thanks for clearing that up. In 5.3, I am not sure if the Custom Approver Determinator (CAD) functionality can be configured to route risks by Risk ID owners in 5.3. In version 5.2/3, I had configured a CAD to detour requests with risks to an approver based upon the combination  "Company Defined in the Request header (e.g. X)+ Role's Functional Area (e.g Finance)", therefore requests containing violations were approved by the required company risk owners, e.g. Company X's Financial Risk Owner (defined in the CAD results)

I don't think I have the answer ito your question in relation to 5.3, but I am sure someone else on the forum may have further advice for you.

All the best.

kevin_tucholke1
Contributor
0 Kudos

Sudhakar,

I don't think that you will be able to do this for Risk Owner as there could me MULTIPLE RISKS on a mitigation control.  However, you stated that you would be ok with Mitigation Approver or Mitigation Monitor.  Both of these are delivered approvers that you can use within your SOD Approval Detour.  With that being said, you will need to require that the Mitigation be applied prior to the time the request access this particular stage for this approval.

This functionality has been enhanced in GRC 10.0, but we are limited to fewer choices when working in AC5.3 in comparison.

Hope this helps.

Kevin Tucholke

Former Member
0 Kudos

Hello All,

Thanks for the reply. As mentioned GRC 5.3 does not route as per Risk id & hence i've forced the step to mitigate the risk in previous stage so that it routes to respective risk owner based on mitigation approver.

Thank you.

Sudhakar S

Answers (2)

Answers (2)

Former Member
0 Kudos

Hello Kaushal & Simon,

Thanks for your response. My Client is on GRC5.3 & need CUP to be config to reroute to respective risk owners based on risk ids? Mitigation Controller / Approver would also suffice fot this purpose. All we need is the request to reroute to respective risk owners based on risk ids for approval.

Sudhakar S

Former Member
0 Kudos

Hi Sudhakar,

SAP have released the following SAP note (manual implementation) to allow this stage/approver setting to be used in GRC 10.0

https://service.sap.com/sap/support/notes/1670504

Hope it helps.

simon_persin4
Contributor
0 Kudos

Alternatively, you can re-create this using BRF+ with the Risk ID as the context result field.

Simon

former_member541582
Participant
0 Kudos

Hi Simon,

Do you happen to know which structure captures the SoD risks in the request?

Thanks and regards,

Vit

simon_persin4
Contributor
0 Kudos

Hi Vit,

Is this a 10.0 query? You can see the structure assignment by using the where used functions in BRF+. have a look around there and if you need further assistance, let me know.

Simon