Epicor Governance, Risk, And Compliance - Epaccsys

Transcription

EpicorGovernance, Risk, andCompliance

Inspiring business pathwaysto a secure, compliant, andsustainable enterprise.

EpicorGovernance, Risk, and ComplianceAchieving visibility and effective controls within the enterprise can be aformidable challenge when many of the processes and procedures inplace remain manual and fragmented. Effective Governance, Risk andCompliance (GRC) initiatives help companies, and their employees staycompliant, and ensure that employees and partners at all levels of theorganization are aware of the associated risks of non-compliance.GRC touches every person and every function in an organization in someway. Whether GRC becomes an intolerable burden that increases companyoverhead or an enabler of efficiency and success depends upon its actual,day-to-day impact on the employees’ work and whether that impact isenabling or debilitating.Financial ManagementSupply Chain ManagementCustomer RelationshipManagementProduction ManagementSales ManagementPlanning and SchedulingHuman CapitalManagementProject ManagementService ManagementProduct Data Management Risk Management Global Trade Compliance Security Management Corporate GovernanceEnvironmental and EnergyManagement

Risk ManagementEnterprise Performance ManagementMany of the requirements for effective GRC programs involveaccelerated disclosure of information to external entities. Thisrequires companies to have better visibility of changes than theyhad in the past. Epicor GRC incorporates the ability to infusebusiness insight through Epicor EPM—a solution that supportsoverall risk management objectives by keeping users abreast ofchanges in the business. For example, Epicor EPM can be setup to alert management of the large credit exposure of one oftheir largest customers or can continuously monitor suppliers foradherence to contractual obligations and cost overrunson projects.Improved Data Governance and Protection with anIntegrated Enterprise SolutionExpectations are rising among auditors, regulatory bodies,customers, and other stakeholders regarding the protectionof corporate information against piracy, fraud, and sabotageconcerns. Enterprise Resource Planning (ERP) systems control themajority of the information that could potentially be at risk. It is not uncommon for companies to use multiple enterprisesoftware solutions in different divisions or business entities.Additionally, they may be running multiple instances or copiesof the same software, and have a variety of stand-alone orpoint solution applications—such as order entry or generalledger—that are not integrated, or at best minimally integrated.There may also be a variety of separate databases, tools, andspreadsheets used for reporting, all which may be generatingdifferent versions of the truth.Cross-Organization Benefits ofIntegrated GRC SolutionThe business environment today requires corporations tomaintain very high standards of corporate governance anddata protection. Most organizations realize that compliancewith regulations that enforce these values actually makes goodbusiness sense, allowing them to reap the benefits of higherprofitability, faster and more accurate reporting and increasedlevels of customer satisfaction. Epicor GRC allows organizationsto embrace data governance and data protection strategies,help control risk, effectively handle regulatory compliance andultimately drive business performance.Security ManagementEpicor GRC provides comprehensive user and group securityto restrict data and application accessibility as needed. Securitycan be granted at user and group levels for all security objectsincluding forms, fields, reports, menus, and method calls. Datatier security is also available for both tables and columns. Thereis also an option to use Microsoft Windows Authentication tosupport a Windows single sign-on and password policy.Automatically track changes with risk mitigation tools such as table andfield level audit capabilities.The only way to truly manage and mitigate risk across theorganization is to have a fully integrated end-to-end solutionproviding your organization with one single, verifiable set offinancial and operational metrics. Epicor GRC provides anintegrated enterprise solution with built-in application-level riskmitigation tools and Business Process Management—providingaudit trails and secure workflow automation, the key elements ofdata integrity and security. With the ability to generate a completeaudit trail of all changes made to the data, Epicor GRC records thewho, what, when, and where of the change regardless of wherethe change originated. When potential security problems arise,the response must be instantaneous. Epicor provides automatedalerting and BPM event capabilities to assist your organization bymanaging these situations in a timely and effective manner.Epicor supports comprehensive management of user, process and datasecurity settings.4

Product SecurityAutomation Tool for EpicorProduct security includes protection to ensure that theapplication only allows use of modules and product variationsthat have been purchased and licensed.The Automation Tool for Epicor (ATE) can do everything yourusers can do in Epicor ERP and is a very efficient way to eitherrun repetitive tasks that may differ only in the selection criteria orrun tasks that need to be launched unattended. ATE can also beused to as part of your change management process to test thelatest Epicor hotfixes using automated test scripts matched toyour business activities and data. Industries that require softwarevalidation matched to intended results will benefit from this tool.Application SecurityApplication security ensures that the business logic protects thedatabase from corruption by always ensuring that an update isvalid, regardless of the source of the transaction. This is necessary ina service-based architecture since the business logic can be calledfrom many environments including a desktop application, externalweb services, browser-based clients, and other smart devices.Credit Card Authorization and EncryptionEpicor credit card authorization used in conjunction with Epicor’snetwork of global payment providers meet Payment CardIndustry standards for data encryption and secure transmissionand storage of sensitive financial credit card information.Access SecurityAccess security verifies that whomever (or whatever) isattempting to access the application server is permitted to do so.This includes login security to the menu system either by entry ofuser ID and password, or via Windows Authentication, sessionsecurity (same as login security) for application components thatare run directly from the desktop or other non-menu areas, andservices security through Epicor to ensure that an external systemmay access the business logic when allowed.Business Process ManagementAs the global regulatory environment grows ever morechallenging for companies, it is becoming increasingly importantto have embedded controls in your enterprise application sothat your users can be more productive. Epicor GRC helps youmove away from the management of day-to-day complianceby leveraging technology and optimizing operational efficiency.Epicor BPM in combination with Epicor Service Connect, allowsyou to identify risky processes to your organization and toeffectively mitigate risk through business-defined workflows.Business SecurityBusiness security includes ensuring that individual users andgroups of users have access to the business functions and datathat they attempt to view or update.Change LogsBPM and Service Connect essentially identify and improveprocesses to make your business more efficient, more disciplined,and better able to adapt to change. BPM is particularly importantwhen it comes to the management of GRC internal controls,processes, and procedures. Many of today’s businesses havealready spent the time and effort to document and outlinetheir business processes, some to meet strict regulatory andquality standards for their industry and others for improvedbusiness efficiency. Epicor incorporates BPM technology toenable organizations to automate, align and streamline businessprocesses for continuous improvement and compliance withGRC guidelines.Automated change logs capture changes as they happen,helping companies better manage the accuracy of data. Thisincludes monitoring all changes to records (before and aftervalues), who made those changes, and when those changeswere made. Users are also prompted for audit notes ofwhy changes have been made. You are also able to createnotifications from change log events using Epicor BusinessActivity Management (BAM).Audit LogsA permanent audit trail of access and changes is the onlyway to validate what is actually happening and to monitorthe preventive controls and processes intended to ensuretransactional validity. The combination of preventive controlswith continuous monitoring gives executives and auditorsthe confidence to attest to financial results and associatedIT controls. Data audit logs support compliance with otherregulations such as FDA Title 21 CFR Part 11, HIPAA, and BaselII to name a few of the more common regulatory requirementsthat companies face.BPM and Service Connect provide a framework for building GRCprocess-driven integration points that give companies seamlessintegration capabilities with other applications and businesses.BPM automates delivery of information to employees internalto your organization that are responsible for managing andmonitoring internal controls. Service Connect logs workflowprocessing for both transactional integrity and compliancy.Service Connect processes are available for review and trackingwhile in progress or after the process completes.5

Epicor Financial Report WriterA standard part of Epicor General Ledger, Epicor Financial ReportWriter provides the ability to meet GRC reporting needs throughcomprehensive financial statement development, reporting anddistribution, including publication out to a spreadsheet.Financial PlannerEnsure transactional integrity and compliancy of data using Epicor BPM tomanage hold and event actions.Epicor Financial Planner is a comprehensive budgeting,forecasting, and planning tool that empowers and simplifiesthe entire ongoing process for organizations. Comprising a fullMicrosoft Excel front end it takes the parts of the budgetingprocess that people are used to without having to learn a newtoolset and extending on this with functions such as spreadingand pulling in actual ERP data. This intuitive interface sits ontop of a secure SQL database that holds all of the budgetinginformation as well as controlling the defined workflow processfor the business and security levels allocated to the budget users.Service Connect WorkflowsAdvanced Financial ReportingEpicor Advanced Financial Reporting (AFR) allows creation,management and viewing of financial data in a user friendlyand easy to manage environment. Financial reports are differentfrom other reports because each line has to be defined in termsof account ranges or sets for which a certain total needs to becalculated, versus other types of reports which do not requiredefinitions of such complex groups. AFR simplifies report creationby exposing a user friendly interface which speaks with the userin financial terms without requiring familiarity with SQL querysyntax or the database structure.Build and execute workflow throughout the system for yourunique business rules.Electronic SignatureInvoke and require electronic signature for processes with secureauthorization and password.Corporate GovernanceThe current business environment is simultaneously complexand increasingly regulated, which can challenge even the largestbusinesses to remain competitive in today’s global markets.This fact is perhaps most important when it comes to financialcontrol—which encompasses all aspects of the financial health ofthe organization. Epicor GRC helps control this risk—effectivelyenabling users to handle regulatory compliance and ultimatelydriving business performance by providing cross-organizationalfinancial visibility and control over financial reporting, planningand forecasting processes.AFR creates reports using the elements familiar to an accountantor financial professional. These include spreadsheet terms suchas Rows and Columns. It also provides an additional element ofreporting hierarchy or trees allowing the viewer to generate thereport for the area of the business which is their responsibility.Because the reports are parameter driven, the viewer cangenerate the report at any time by selecting the parametersof time, company, Book or organizational element as requiredwithout the need for intervention by the financial team.AFR helps organizations support GAAP, IFRS andSarbanes-Oxley regulations.Organizations are under increased pressure to file accuratefinancial results in a timely manner. While spreadsheets mayhave provided an adequate solution in the past, as reportingdeadlines shrink and controls become more stringent, they willno longer be a viable option. Epicor GRC can help organizationsmeet these shortened deadlines in a variety of ways—fromconsolidating financial information to providing drill-down anddrill-across access from financial reports to transactional detail.Bottom line, when companies adequately report, plan, budget,forecast, and periodically review and update budgets andforecasts, they exhibit a more mature level of internal control. Acompany that is unable to perform these functions well can playa major part in motivating financial fraud and not living up tothe tenets of financial laws and legislation. Integrated enterprisesoftware applications go a long way in helping organizationsdocument their internal controls, remove manual processes, andachieve greater visibility to their financial data.Manage, report, and distribute financial information securely.6

Global Trade ComplianceInternational Shipping and DocumentationEpicor GRC supports integration with manifesting andinternational export shipment processing solutions, whichprovides for functionality to track hazardous material shippingfor both domestic and international shipments. There is alsosupport for international trade agreements such as NAFTA.Epicor GRC can also provide the harmonized tariff schedule (HTS)codes, which determine eligibility for preferential status underinternational trade agreements such as NAFTA, and print thenecessary export documents as part of the internationalshipping process.In order to conduct business globally, you need enterprisebusiness software that enables compliance with local laws,satisfies international security measures and meets the myriadof local and regional documentation requirements. Epicorapplications provide a comprehensive platform for managingthese trade compliance necessities.Global Trade Standards—ItemsEpicor GRC allows for the definition of the global trade standardsfor items, such as UPC UCC-12, EAN UCC-13, EAN UCC-8,and GTIN-14. Application functionality allows for a global tradestandard to apply to an item and in the process creates a globaltrade standard bar code which is able to be scanned on any partnumber field.Landed CostLanded cost functionality offers significant benefits for customerswho import or ship in materials either for resale or for use inmanufacturing. The cost of freight, insurance and import dutiescan have a big impact on margins. This functionality allowsbusinesses to track costs accurately against the parts to whichthey apply, ensuring that the selling or assembly price thenreflects the true cost of the materials, parts or finished goods.Country of OriginEpicor GRC supports the needs of manufacturers and distributorsby tracking Country of Origin, which supports the percentof Content by Country requirements that are needed for ISOextension in Europe.Track and manage compliance status of parts subject tointernational directives.RoHS/WEEE ComplianceQuality ManagementThe Restrictions of Hazardous Substances (RoHS) directive andWaste Electrical and Electronic Equipment directive (WEEEDirective) set collection, recycling and recovery targets forelectrical goods and are primarily directives that affected allcompanies selling electronic equipment into the European Union(EU). Epicor GRC supports tracking the compliance status ofparts in accordance with various legislative requirements whilealso tracking the ultimate consumption and disposal of thosetargeted parts to ensure the proper compliance with RoHS andWEEE directives.Industry and regulatory compliance requires three basiccapabilities: process control, documentation and visibility.The Compliance & Audit solution, implemented in concertwith Epicor Advanced Quality Management core capabilities,enables you to automate your business processes, share keyinformation, provide process documentation, traceability, andtrack existing and potential issues through effective resolution.Epicor Advanced Quality Management provides audit trailvisibility of inventory transactions occurring in inspection andduring discrepant material report (DMR) processing. Additionally,to help businesses manage compliance documentation such asCertificates of Analysis (COA), Certificates of Quality (COQ), orCertificates of Compliance, Epicor includes the ability to checkfor Certificates of Compliance at receiving of materials fromsuppliers, receiving of in-process parts from outside operationsuppliers, and before shipping products to customers.Product Lifecycle ManagementEpicor PLM serves as a central knowledge repository forprocess and product history, and promotes integration anddata exchange among all enterprise users who interact withproducts. Epicor PLM offers integration with more than twelveCAD systems while managing all documentation associated witha product throughout its entire lifecycle. Additionally, EpicorPLM supports GRC initiatives through sophisticated documentmanagement, critical for those organizations that need excellentaudit tracking and control of documentation across theenterprise, including support for RoHS.With planning to production coverage for quality, EpicorAdvanced Quality Management puts companies in a constantstate of compliance. Quality Performance Management providesturnkey support for ISO, automotive (TS), aerospace (AS), andFDA (cGMP, FDA 21 CFR Part 11).7

Environmental andEnergy ManagementLogisticsLogistics software can manage the fastest distance from pointto point; reduce fuel used and carbon emissions created duringtransport. Truck route optimization is at the heart of logisticsbenefit to CSR. The value of logistic applications is as simple asgetting from point A to point B: optimized trucking and shippingroutes mean less miles traveled, less miles traveled means lessgas used by trucks, less gas used by trucks means less CO2emissions. Epicor has strategic relationships with industry leadinglogistics providers such as Appian Logistics Software to supportyour needs for strong logistics management.As the world continues to analyze energy availability and thelong-term effects of climate change, businesses too are turningtheir attention to areas of opportunity—reduction of carbonemissions, energy conservation and supply chain sustainability.Despite the fact that government incentives in this area are stillin their infancy, many businesses are finding that these initiativesgo beyond simple good-citizenship to real business opportunitiesand bottom line savings that can contribute financial value to theorganization while meeting demanding customer requirements.Lean PrinciplesIn the near future, having the ability to maintain and trackcarbon emissions will become a much more strategic initiativewithin most organizations. While an emerging area of business,Epicor has many solutions that are targeted at environmentaland energy management.One way for manufacturing and distribution based companiesto enable supply chain sustainability across their extendedorganization is to implement and follow lean principles withintheir respective organizations. Epicor supports the underlyingprinciples of lean manufacturing and distribution by enablingprocess improvement initiatives meant to build effectiveness andefficiency across the entire supply chain.Companies will look to IT and software solutions to helpthem find opportunities to be better stewards of theenvironment and extend the tangible benefits of corporate socialresponsibility (CSR) through the extended supply chain. Some ofthe more notable areas that corporations areplacing emphasis on when deciding on a path to goodenvironmental and energy management surround strategicsourcing and procurement, logistics, application of leanprinciples, and virtualization.VirtualizationThe introduction of virtualization technology into enterpriseapplications can lead to a significant reduction in energyconsumption, as there are fewer physical servers to power,and less cooling is required to dissipate the heat these serversgenerate. Energy consumption is rapidly becoming a far fromtrivial issue for organizations. Epicor supports efforts to conserveenergy by providing the delivery of enterprise applicationsthrough the use of virtualization technology.Energy MonitoringWith Energy Monitoring from Epicor Mattec MES, you cansolve even the most complicated energy use and planningproblems. We help businesses reduce energy consumption andpinpoint energy savings opportunities right at the source–bymonitoring energy use on equipment. It doesn’t matter whatyour energy agenda or focus is, we can give you the powerto achieve your goals; ISO 50001, ISO 14001, SEP, energysavings, environmental policies, sustainable practices, corporatecitizenship, and social responsibility.About EpicorEpicor Software Corporation is a global leader delivering businesssoftware solutions to the manufacturing, distribution, retail,and service industries. With more than 40 years of experience,Epicor has more than 20,000 customers in over 150 countries.Epicor solutions enable companies to drive increased efficiencyand improve profitability. With a history of innovation, industryexpertise and passion for excellence, Epicor inspires customers tobuild lasting competitive advantage. Epicor provides the singlepoint of accountability that local, regional, and global businessesdemand. For more information, visit www.epicor.com.Ensure optimized delivery routes and lower miles traveled by your fleet,ultimately reducing costs and carbon emissions.8

For more information or to talkto one of our ERP consultantsabout your requirements pleaseget in touch:solutions@epaccsys.com 44 (0) 116 248 7518www.epaccsys.comThe contents of this document are for informational purposes only and are subject to change without notice. Epicor Software Corporation makesno guarantee, representations or warranties with regard to the enclosed information and specifically disclaims, to the full extent of the law, anyapplicable implied warranties, such as fitness for a particular purpose, merchantability, satisfactory quality or reasonable skill and care. Thisdocument and its contents, including the viewpoints, dates and functional content expressed herein are believed to be accurate as of its date ofpublication, April 2014. The usage of any Epicor software shall be pursuant to the applicable end user license agreement and the performance ofany consulting services by Epicor personnel shall be pursuant to applicable standard services terms and conditions. Usage of the solution(s)described in this document with other Epicor software or third party products may require the purchase of licenses for such other products. Epicor,Business Inspired, and the Epicor logo are registered trademarks or trademarks of Epicor Software Corporation, registered in the United States andcertain other countries.Microsoft and Windows are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries.Apple, iPad, and iPod are either registered trademarks or trademarks of Apple Inc., registered in the United States and other countries. Google is atrademark of Google Inc. in the United States and/or other countries. Magento is either a registered trademark or a trademark of Magento (adivision of X.commerce, Inc.), registered in the United States and other countries. All other trademarks mentioned are the property of theirrespective owners. 2014 Epicor Software Corporation. All rights reserved.

compliant, and ensure that employees and partners at all levels of the organization are aware of the associated risks of non-compliance. GRC touches every person and every function in an organization in some way. Whether GRC becomes an intolerable burden that increases company overhead or an enabler of efficiency and success depends upon its .