Abiomed Inc. Implements ControlPanelGRC for Compliance
Abiomed Inc. (Danvers, MA) is using ControlPanelGRC, SymSoft Corp.’s (Milwaukee, WI) second-generation suite of modular, integrated GRC applications that address the major areas of compliance. Abiomed provides medical devices that provide circulatory support to acute heart failure patients. The company implemented ControlPanelGRC in just three days.
Like many smaller, regulated enterprises, Abiomed, which went public in 1994, is required under Sarbanes-Oxley legislation to operate its SAP systems according to many of the same standards as large publicly traded enterprises. With a small IT staff and numerous initiatives, Abiomed has been able to turn regulatory pain into gain and reduce its Total Cost of Compliance. In addition, the 27-year-old company has streamlined costs and made its compliance mandates easier, quicker, and more efficient to complete. Moreover, it has established a pro-active working relationship with internal and external auditors.
“ControlPanelGRC enables me to have clear visibility into issues and risks faced by our company, and all the tools are in one, nice front-end menu,” says Sharon Kaiser, chief information officer, Abiomed. “I now have access to dashboards that provide a high-level view, and if something piques my interest, I can easily drill down further into the details.”
ControlPanelGRC has enabled Abiomed to mitigate risks and reduce very costly, labor-intensive audit and compliance processes. ControlPanelGRC Risk Analyzer and Usage Analyzer, two modules of the solution, automate reports on potential Conflict of Duties and identify anyone who has executed a potential risk.
“There are probably four to five of the 13 IT general controls that I can now move directly into ControlPanelGRC,” Kaiser says. “When auditors visit, they can now view much of the information online that previously we were compiling manually. Our manager of applications would spend about 10 hours a quarter pulling and distributing Segregation of Duties analysis reports for review and approval. Now, ControlPanelGRC creates and routes the SOD reports for him.”
Abiomed was familiar with ControlPanelGRC through its successful three-year partnership with Symmetry Corp., a provider of SAP Basis and Security support, and a reseller of ControlPanelGRC solutions. Before deploying the entire solution, Abiomed used ControlPanelGRC Transport Manager, which automates the approval and transport of SAP functional changes into production.
“We are grateful for our partnership with Abiomed, an innovator whose artificial-heart technology and cardiac-assist devices are saving people’s lives,” says Dan Wilhelms, president and CEO of SymSoft. “In a very important way, ControlPanelGRC’s embedded compliance and accelerated workflows improve data access and reporting so corporate executives can focus on innovative discoveries and drive more value to their enterprises.”
ControlPanelGRC integrates SymSoft’s security and transport tools into a single compliance solution. The product’s seven modules go beyond the Segregation of Duties dictated by Sarbanes-Oxley to complement and extend any pre-installed GRC solution.
“I think ControlPanelGRC has been one of the few software applications that went in very quickly and smoothly, and delivered immediate returns the first day we started using it,” Kaiser says. “It’s there, it works, it’s what they said it would be, and we’re just looking to see how we can use it more.”