Would you rate this risk as ‘High’ or ‘Medium’ priority? Please motivate! (Tip: think about the potential additional control to be implemented to mitigate the SOD risk).
- It is relatively easy to mitigate this risk by implementing extra controls on creation of new vendors and/or approval of purchase orders. If the SAP system is configured in the way that such additional controls are enforced we would rate the risk as medium. Else the risk is High.