GRUPO MODELO:
Brewing Success Through the Use of SAP GRC Technology
BY:
Issac Askarinam • Cathy Kang • Chloe Kim • Hanna You
Honor Code
We pledge on our honor that we have not given or received any unauthorized assistance
on this project”
Table of Contents
Page
Honor
Code………………………………………………………………………………………………………………….i
Table of
Contents……………………………………………………………………………………………………………..ii
Executive
Summary…………………………………………………………………………………………………………iii
I. Grupo Modelo’s
Background………………………………………………………………………………….1
II. New Business Objective and
Goals………………………………………………………………………….1
III. Governance, Risk Management, and Compliance………………………………..1
a. Governance………………………………………………………………………………………………..2
b. Risk Management……………………………………………………………………………………….2
c. Compliance………………………………………………………………………………………………..2
IV. Adoption of SAP’s GRC
Technology……………………………………………………………………….2
a. SAP Access Control……………………………………………………………….3
b. SAP Risk Management…………………………………………………………..3
c. SAP Process Control………………………………………………………………4
V. Implementation of SAP GRC
Technology ……………………………………………………………….5
a. Goal #1…………………………………………………………………………….5
b. Goal #2…………………………………………………………………………….6
c. Goal #3…………………………………………………………………………….6
d. Goal #4…………………………………………………………………………….6
e. Goal #5…………………………………………………………………………….6
VI. Competitive Advantage Through Use of SAP GRC
Technology…………………………………6
VII. Benefits of Using SAP GRC
Technology………………………………………………………………….7
a. Improved Governing Framework………………………………………………………………….7
b. Better Controls……………………………………………………………………………………………8
c. Lessened Segregation of Duties…………………………………………………………………….9
VIII. Final
Thoughts…………………………………………………………………………………………………….9
IX. Annotated
Bibliography………………………………………………………………………………………..11
Executive Summary
The purpose of this project was to describe how Grupo Modelo has used SAP GRC
technology to accomplish their new business objective of aligning all internal processes.
Research for this report included a review of multiple reports from Grupo Modelo, a senior
member at SAP, advisory firms such as Ernst and Young and Deloitte, the Wall Street
Journal, and several other reputable sources.
Our research indicates that by implementing SAP GRC technology, Grupo Modelo was
able to gain numerous organizational benefits, as well as an advantage over its competitors
by transforming into a process oriented company.
While Grupo Modelo faced management challenges prior to the implementation of SAP
GRC, Grupo Modelo has now successfully syndicated the internal processes of the
company, simplified the management of numerous distributions and business operations,
and successfully applied information technology to obtain an advantage in the beer
brewing industry.
Grupo Modelo’s Background
Since its inception in 1925, Grupo Modelo has been one of the largest beer brewing
companies in the world. With popular brands such as Corona, Modelo, and Victoria, Grupo
Modelo’s beers are universally adored and are sold in over 180 countries around the world
(Grupo Modelo, 2011, p. 1).
One of the biggest advantages Grupo Modelo has over its competitors is that it has vast
distribution networks and nearly 100 business units worldwide. These business units range
from breweries to distribution centers. However, these advantages also create a huge
problem for Grupo Modelo. Modelo’s problem is that their upper management has to keep
track of all the activities of each business unit and distribution network (Murphy, 2013, p.
1). The process of keeping track of every distribution network and business unit can be
tremendously difficult and time consuming for upper management. As a result of this
problem, Modelo’s upper management will also have difficulty responding to the different
financial and operating threats that are present within each business unit and distribution
network.
New Business Objective and Goals
In an attempt to overcome this issue, Grupo Modelo developed a new business objective –
which sought to “align all internal processes across the business” (Murphy, 2013, p. 2). By
aligning the internal processes of each distribution network and business unit, Modelo’s
upper management would have greater control and monitoring ability over every aspect of
the entire organization. In order to successfully accomplish their new business objective,
Modelo would have to adapt its governance, risk management, and compliance (GRC)
practices; so that ultimately their “business practices and rules [would be aligned]
company-wide” (Murphy, p. 1) But what exactly is GRC?
Governance, Risk Management, and Compliance
Denise Vu Broady – SAP’s current Global Vice President of Competitive and Market
Intelligence – states that GRC is like a “central nervous system that helps [an organization]
manage [their] business more effectively” (Broady, 2008, p. 9). The purpose of GRC is to
help an organization efficiently put policies and controls in place. Essentially, GRC makes
sure an organization does things the right way. It keeps track of what an organization is
doing and raises alerts to upper management when things start to go off track or when risk
is inevitable. GRC involves a company’s approach in following three areas:
Governance
Governance involves the overall management approach through which CEOs and Senior
Executives direct and control the entire organization. In a typical organization, upper
management will ask itself the following questions regarding governance: How are we
making sure that the right policies and procedures are in place to run the company
efficiently? How are those policies communicated to our employees? What sort of
checking is done to make sure that the policies and procedures are being followed (Broady,
Ch. 1)?
Risk Management
Risk Management involves the processes through which upper management identifies,
analyzes, and responds to the risks that affects their organization. In a typical organization,
upper management will ask itself the following questions regarding risk management:
How should risk be monitored? How much risk is involved in certain corporate projects
and activities? Which corporate strategies should be pursued given the associated risks?
(Broady, Ch. 1)
Compliance
Compliance involves meeting the applicable rules, regulations, and conditions. These
rules, regulations, and conditions can be set by an external figure (e.g. a government
regulator or a foreign country) or an internal figure (e.g. the CEO or upper management).
In a typical organization, upper management will ask itself the following questions
regarding compliance: How can we comply with the financial regulations established by
the Sarbanes-Oxley Act? How can we comply with the international trade regulations
established by other countries? How can each of our business units effectively comply