SlideShare a Scribd company logo
ERP in the Cloud
Chris Kenny
Manager, Technology Risk Services
11 October 2016
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Overview
• Introduction
• ERP and the cloud
• Risks and Controls
• Cloud ERP in practice – Case study
• Final thoughts
© 2016 Grant Thornton UK LLP. All rights reserved | Public
About Grant Thornton
Grant Thornton UK LLP
 UK member firm of Grant Thornton
International Ltd
 Turnover of £521 million
 Led by over 180 partners, with
4,500 people
 Operates from 26 offices
© 2016 Grant Thornton UK LLP. All rights reserved | Public
About me
• Eight years experience in internal audit
• Manage the delivery of ERP, internal and external audit services across
the Midlands region
• CMIIA and CISA qualified
© 2016 Grant Thornton UK LLP. All rights reserved | Public
What do we mean by
ERP?
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Characteristics of an ERP system
• single integrated database
• modular
• common user interface
• follow good business practices
• flexible and adaptable
• workflow
• automation
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Evolution of ERP
• 1980's
• mainframe
• time sharing
• finance orientated
• green screen
• 1990's
• client-server
• real-time
• GUI
• full business operations
• 2010's
• focus on UX
• data analytics
• the cloud
• 2000's
• web-enabled
© 2016 Grant Thornton UK LLP. All rights reserved | Public
ERP in the cloud
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Cloud services
Public Private
Hybrid
© 2016 Grant Thornton UK LLP. All rights reserved | Public
On-Premise Iaas Paas SaaS
Application
Database
O/S
Hardware
ERP in the cloud example
© 2016 Grant Thornton UK LLP. All rights reserved | Public
What does the marketplace look like?
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Business drivers
Reduce costs
Speed of deployment
Scalability and adaptability
Accessibility
Modernity
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Risk & Controls
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Model of internal audit involvement
Due diligence
• Asses
risk and
control
Project
implementation
• Asses
risk and
control
Post
implementation
/ BAU
• Asses
risk and
control
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Customisation & integration
Performance, cost and SLAs
Information governance
Information security
Business & strategic fit
Due Diligence
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Project implementation
Risk management
Internal controls
Segregation of duties
Gateway or milestone reviews
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Post-implementation / BAU
Monitor security
Change management
Benefits realisation
Contract management
© 2016 Grant Thornton UK LLP. All rights reserved | Public
• obtain and review the SOC1/2 or equivalent
• right to audit
• change management
• review the security model, including segregation of duties and starters / leavers
• review change management procedures
• involve other SME's: Legal, Data Protection, Project Management
Key actions for internal audit
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Case study
© 2016 Grant Thornton UK LLP. All rights reserved | Public
• Large subsidiary business unit of a FTSE100 retail business
• Implementing Oracle Cloud ERP (HCM, Finance, CRM)
• Newness of Fusion
• Project management challenges
Key issues and challenges
© 2016 Grant Thornton UK LLP. All rights reserved | Public
• Required a wide-mix of skills within the audit team by reviewing areas
including:
─ compliance with data protection legislation
─ disaster recovery
─ capacity and performance management
─ IT general controls and key financial controls
─ contractual arrangements between the client and Oracle.
Our approach
© 2016 Grant Thornton UK LLP. All rights reserved | Public
• Change of business case impacted project benefits and caused delays
• PII accessible outside the EEA
• Key financial controls not implemented correctly
• Volume and completeness of UAT
• RBAC and SoD issues
• SOC 1 report out of date
Audit Findings
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Conclusions
© 2016 Grant Thornton UK LLP. All rights reserved | Public
The future
• The inevitable cyber breach
• death of on-premise – but not for a while!
• the Internet of Things
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Conclusion
• Cloud ERP presents a number of
opportunities for organisations
• Cannot outsource risk however!
• Aim to be involved at all stages of
the lifecycle
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Questions?
© 2016 Grant Thornton UK LLP. All rights reserved | Public
Further Reading
• ‘The Treacherous Twelve’ Cloud Computing Top Threats in 2016
─ https://cloudsecurityalliance.org/download/the-treacherous-twelve-cloud-
computing-top-threats-in-2016/
• 'Service Organization Control (SOC) Reports'
─ http://www.aicpa.org/soc
‘Grant Thornton’ refers to the brand under which the Grant Thornton member firms provide
assurance, tax and advisory services to their clients and/or refers to one or more member
firms, as the context requires.
Grant Thornton UK LLP is a member firm of Grant Thornton International Ltd (GTIL).GTIL and
the member firms are not a worldwide partnership. GTIL and each member firm is a separate
legal entity. Services are delivered by the member firms. GTIL does not provide services to
clients. GTIL and its member firms are not agents of, and do not obligate, one another and are
not liable for one another’s acts or omissions.
grantthornton.co.uk
© 2016 Grant Thornton UK LLP. All rights reserved | Public

More Related Content

PPTX
Lufthansa Reference Architecture for the OpenGroup
PDF
ERP Cloud: Assessing Readiness and Building the Roadmap
PDF
Stopping the Lake from becoming a Swamp
PPTX
Louisiana Pacific's Seamless Migration of ERP
PDF
Business Case Calculator for DevOps Initiatives - Leading credit card service...
PPTX
Why Zenoss is Right for You
PDF
Ecosystems - Drive improvement from Holistic Insight
PDF
SAP Transformation: Cloud Advantage
Lufthansa Reference Architecture for the OpenGroup
ERP Cloud: Assessing Readiness and Building the Roadmap
Stopping the Lake from becoming a Swamp
Louisiana Pacific's Seamless Migration of ERP
Business Case Calculator for DevOps Initiatives - Leading credit card service...
Why Zenoss is Right for You
Ecosystems - Drive improvement from Holistic Insight
SAP Transformation: Cloud Advantage

What's hot (20)

PPTX
FCCS Oracle Close Up Q4-2017
PPTX
CapEx vs OpEx for IT & Cloud
PDF
From ITOM to DevOps v1
PDF
L’ Iperconvergenza di nuova generazione ridefinisce economics e operation del...
PPTX
Altius, Inc_Overview
PDF
Implats Cloud Journey
PPTX
Datacomm Cloud Business Media Briefing
PDF
Oracle Code Beijing/Sydney APIM & Microservices: A Match Made in Heaven
PPTX
Digital transformation and the role of cloud computing Capgemini Mark Skilt...
PDF
SOUG Day - autonomous what is next
PPTX
Rethinking People Costs in Enterprise IT
PDF
GF_Presentation
PPTX
Running GxP Compliant SAP Workloads on AWS
PDF
Breaking Down a SQL Monolith with Change Tracking, Kafka and KStreams/KSQL
PDF
Introducing elastic.io iPaaS: Best-of-Breed Integrations - New in 2017
PPTX
Episode 1: Transition to Iaas
PPTX
Digital Transformational Trends in Insurance
PPTX
Nam Khong - SAP on Cloud for Your Intelligent Enterprise
PDF
3 Keys to Success from MetLife’s HCM Cloud, Payroll & Analytics Go-Live with ...
 
PDF
IT-as-a-Service (ITaaS) - The New Business Model for IT
FCCS Oracle Close Up Q4-2017
CapEx vs OpEx for IT & Cloud
From ITOM to DevOps v1
L’ Iperconvergenza di nuova generazione ridefinisce economics e operation del...
Altius, Inc_Overview
Implats Cloud Journey
Datacomm Cloud Business Media Briefing
Oracle Code Beijing/Sydney APIM & Microservices: A Match Made in Heaven
Digital transformation and the role of cloud computing Capgemini Mark Skilt...
SOUG Day - autonomous what is next
Rethinking People Costs in Enterprise IT
GF_Presentation
Running GxP Compliant SAP Workloads on AWS
Breaking Down a SQL Monolith with Change Tracking, Kafka and KStreams/KSQL
Introducing elastic.io iPaaS: Best-of-Breed Integrations - New in 2017
Episode 1: Transition to Iaas
Digital Transformational Trends in Insurance
Nam Khong - SAP on Cloud for Your Intelligent Enterprise
3 Keys to Success from MetLife’s HCM Cloud, Payroll & Analytics Go-Live with ...
 
IT-as-a-Service (ITaaS) - The New Business Model for IT
Ad

Viewers also liked (13)

PDF
A Comparison of Cloud based ERP Systems
PDF
Cloud ERP vs. On-Premise ERP: Dissecting the Controversy
 
PDF
Enterprise Resource Planning (ERP) in Cloud
PPTX
Cloud vs on premise erp
PPTX
Is ERP on Cloud the next step for your business? | Cloud ERP Benefits
PPTX
Aspire Global Enterprise Solutions - ERP on Cloud delievered
PPTX
Top 6 Advantages Of Using Cloud erp software For Your Business
PPTX
Comparision of ERP Vendors
PDF
The Top 7 Considerations When Comparing Cloud vs. Premise-Based Contact Centers
PPTX
How a CPA Can Leverage Cloud ERP to Improve Client Relationships
 
PPTX
Cloud vs.data center
PPT
Cloud versus On Premise
PPT
Involving the user in your design with the Behavioural Lenses - MEDICA Trade ...
A Comparison of Cloud based ERP Systems
Cloud ERP vs. On-Premise ERP: Dissecting the Controversy
 
Enterprise Resource Planning (ERP) in Cloud
Cloud vs on premise erp
Is ERP on Cloud the next step for your business? | Cloud ERP Benefits
Aspire Global Enterprise Solutions - ERP on Cloud delievered
Top 6 Advantages Of Using Cloud erp software For Your Business
Comparision of ERP Vendors
The Top 7 Considerations When Comparing Cloud vs. Premise-Based Contact Centers
How a CPA Can Leverage Cloud ERP to Improve Client Relationships
 
Cloud vs.data center
Cloud versus On Premise
Involving the user in your design with the Behavioural Lenses - MEDICA Trade ...
Ad

Similar to ERP in the Cloud_ck_v2 (20)

PDF
Nfp Seminar Series Danny November 18 Emerging Technology Challenges And...
PPT
Technology And Enterprise Forum, May 2011
PPTX
Iia 2012 Spring Conference Philly V Final
PDF
Technology Risk Services
DOCX
Cloud Computing - Emerging Opportunities in the CA Profession
PDF
#OOW16 - Risk Management Cloud / GRC General Session
PDF
Cybersecurity It Audit Services Gt April2012
PPTX
HEUG presentation 23rd Oct 2019 - Dawn McKenzie (Inoapps).pptx
PPT
Presentation to Irish ISSA Conference 12-May-11
PPTX
Espion and SureSkills Presentation - Your Journey To A Secure Cloud
PDF
Cloud Organizational impact, Emerging trends
PDF
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]
PDF
The benefits of cloud technology for remote working
PDF
The benefits of cloud technology for remote working
PPTX
Positive Hack Days. Christopher Gould. Head in the Clouds…Can we overcome sec...
PPT
Cloud Computing and Records Management
PDF
Cloud Computing for CPAs: What Your Client Will Ask You
PPTX
Concerned About Vendor Management 10 30 12
PDF
Top 10 Reasons to Choose Oracle ERP Cloud Financials
PDF
Best Practices for ERP Cloud Migrations: A CFO Guidebook
Nfp Seminar Series Danny November 18 Emerging Technology Challenges And...
Technology And Enterprise Forum, May 2011
Iia 2012 Spring Conference Philly V Final
Technology Risk Services
Cloud Computing - Emerging Opportunities in the CA Profession
#OOW16 - Risk Management Cloud / GRC General Session
Cybersecurity It Audit Services Gt April2012
HEUG presentation 23rd Oct 2019 - Dawn McKenzie (Inoapps).pptx
Presentation to Irish ISSA Conference 12-May-11
Espion and SureSkills Presentation - Your Journey To A Secure Cloud
Cloud Organizational impact, Emerging trends
Digital Transformation in the Cloud: What They Don’t Always Tell You [2020]
The benefits of cloud technology for remote working
The benefits of cloud technology for remote working
Positive Hack Days. Christopher Gould. Head in the Clouds…Can we overcome sec...
Cloud Computing and Records Management
Cloud Computing for CPAs: What Your Client Will Ask You
Concerned About Vendor Management 10 30 12
Top 10 Reasons to Choose Oracle ERP Cloud Financials
Best Practices for ERP Cloud Migrations: A CFO Guidebook

ERP in the Cloud_ck_v2

  • 1. ERP in the Cloud Chris Kenny Manager, Technology Risk Services 11 October 2016
  • 2. © 2016 Grant Thornton UK LLP. All rights reserved | Public Overview • Introduction • ERP and the cloud • Risks and Controls • Cloud ERP in practice – Case study • Final thoughts
  • 3. © 2016 Grant Thornton UK LLP. All rights reserved | Public About Grant Thornton Grant Thornton UK LLP  UK member firm of Grant Thornton International Ltd  Turnover of £521 million  Led by over 180 partners, with 4,500 people  Operates from 26 offices
  • 4. © 2016 Grant Thornton UK LLP. All rights reserved | Public About me • Eight years experience in internal audit • Manage the delivery of ERP, internal and external audit services across the Midlands region • CMIIA and CISA qualified
  • 5. © 2016 Grant Thornton UK LLP. All rights reserved | Public What do we mean by ERP?
  • 6. © 2016 Grant Thornton UK LLP. All rights reserved | Public Characteristics of an ERP system • single integrated database • modular • common user interface • follow good business practices • flexible and adaptable • workflow • automation
  • 7. © 2016 Grant Thornton UK LLP. All rights reserved | Public Evolution of ERP • 1980's • mainframe • time sharing • finance orientated • green screen • 1990's • client-server • real-time • GUI • full business operations • 2010's • focus on UX • data analytics • the cloud • 2000's • web-enabled
  • 8. © 2016 Grant Thornton UK LLP. All rights reserved | Public ERP in the cloud
  • 9. © 2016 Grant Thornton UK LLP. All rights reserved | Public Cloud services Public Private Hybrid
  • 10. © 2016 Grant Thornton UK LLP. All rights reserved | Public On-Premise Iaas Paas SaaS Application Database O/S Hardware ERP in the cloud example
  • 11. © 2016 Grant Thornton UK LLP. All rights reserved | Public What does the marketplace look like?
  • 12. © 2016 Grant Thornton UK LLP. All rights reserved | Public Business drivers Reduce costs Speed of deployment Scalability and adaptability Accessibility Modernity
  • 13. © 2016 Grant Thornton UK LLP. All rights reserved | Public Risk & Controls
  • 14. © 2016 Grant Thornton UK LLP. All rights reserved | Public Model of internal audit involvement Due diligence • Asses risk and control Project implementation • Asses risk and control Post implementation / BAU • Asses risk and control
  • 15. © 2016 Grant Thornton UK LLP. All rights reserved | Public Customisation & integration Performance, cost and SLAs Information governance Information security Business & strategic fit Due Diligence
  • 16. © 2016 Grant Thornton UK LLP. All rights reserved | Public Project implementation Risk management Internal controls Segregation of duties Gateway or milestone reviews
  • 17. © 2016 Grant Thornton UK LLP. All rights reserved | Public Post-implementation / BAU Monitor security Change management Benefits realisation Contract management
  • 18. © 2016 Grant Thornton UK LLP. All rights reserved | Public • obtain and review the SOC1/2 or equivalent • right to audit • change management • review the security model, including segregation of duties and starters / leavers • review change management procedures • involve other SME's: Legal, Data Protection, Project Management Key actions for internal audit
  • 19. © 2016 Grant Thornton UK LLP. All rights reserved | Public Case study
  • 20. © 2016 Grant Thornton UK LLP. All rights reserved | Public • Large subsidiary business unit of a FTSE100 retail business • Implementing Oracle Cloud ERP (HCM, Finance, CRM) • Newness of Fusion • Project management challenges Key issues and challenges
  • 21. © 2016 Grant Thornton UK LLP. All rights reserved | Public • Required a wide-mix of skills within the audit team by reviewing areas including: ─ compliance with data protection legislation ─ disaster recovery ─ capacity and performance management ─ IT general controls and key financial controls ─ contractual arrangements between the client and Oracle. Our approach
  • 22. © 2016 Grant Thornton UK LLP. All rights reserved | Public • Change of business case impacted project benefits and caused delays • PII accessible outside the EEA • Key financial controls not implemented correctly • Volume and completeness of UAT • RBAC and SoD issues • SOC 1 report out of date Audit Findings
  • 23. © 2016 Grant Thornton UK LLP. All rights reserved | Public Conclusions
  • 24. © 2016 Grant Thornton UK LLP. All rights reserved | Public The future • The inevitable cyber breach • death of on-premise – but not for a while! • the Internet of Things
  • 25. © 2016 Grant Thornton UK LLP. All rights reserved | Public Conclusion • Cloud ERP presents a number of opportunities for organisations • Cannot outsource risk however! • Aim to be involved at all stages of the lifecycle
  • 26. © 2016 Grant Thornton UK LLP. All rights reserved | Public Questions?
  • 27. © 2016 Grant Thornton UK LLP. All rights reserved | Public Further Reading • ‘The Treacherous Twelve’ Cloud Computing Top Threats in 2016 ─ https://cloudsecurityalliance.org/download/the-treacherous-twelve-cloud- computing-top-threats-in-2016/ • 'Service Organization Control (SOC) Reports' ─ http://www.aicpa.org/soc
  • 28. ‘Grant Thornton’ refers to the brand under which the Grant Thornton member firms provide assurance, tax and advisory services to their clients and/or refers to one or more member firms, as the context requires. Grant Thornton UK LLP is a member firm of Grant Thornton International Ltd (GTIL).GTIL and the member firms are not a worldwide partnership. GTIL and each member firm is a separate legal entity. Services are delivered by the member firms. GTIL does not provide services to clients. GTIL and its member firms are not agents of, and do not obligate, one another and are not liable for one another’s acts or omissions. grantthornton.co.uk © 2016 Grant Thornton UK LLP. All rights reserved | Public