Global specialty vehicle manufacturer reduces auditing costs by 90% with Infor Governance, Risk, and Compliance

Infor_3D Platform Image_Library_Dark_06.jpg

December 12, 2024By Mona Patel | Industry & Solution Strategy Director - Infor Platform Technology

  

Miller Industries, Inc. ("Miller Industries") is the world’s largest manufacturer of towing and recovery equipment. To put it in perspective, their equipment is what helps when your car breaks down on the side of the road or when roadways need to be cleared after an accident.

Founded in 1990 by Bill Miller, Miller Industries has grown into a $1.15 billion company with manufacturing facilities worldwide. As a publicly traded company, compliance is crucial to protecting investors and minimizing the risk of financial fraud or unauthorized access to sensitive data. When Miller Industries transitioned to Infor CloudSuite Automotive in 2021, Infor Governance, Risk, and Compliance (GRC) gave them the confidence to adopt a new cloud ERP system, ensuring secure access controls while still enabling users to perform their daily tasks efficiently

“Infor GRC streamlines the manual processes we previously relied on. It offers monitoring and reporting, making it a solution that can quickly provide insights to address any issues that arise.”- Debbie Whitmire, Chief Financial Officer

Global specialty vehicle manufacturer reduces auditing costs by 90% with Infor Governance, Risk, and Compliance

Infor GRC Authorizations Insight replaces manual, negative testing

Although Miller Industries is a public company, it operates with a lean workforce of just 1,600 employees. It's common for staff to take on multiple roles or responsibilities. Additionally, each manufacturing facility has its own staffing structure, adding complexity to managing standardized roles across the organization. As a result, ensuring there was Segregation of Duties (SoD) without placing constraints for users to perform their jobs was challenging.

Before implementing Infor GRC, managing SoD involved a manual process called "negative testing," where individual testing was conducted to determine what an employee could or could not do. This process had to be repeated each time a user was added or changed roles. It was an ongoing effort, not just an annual exercise for auditors.

With Infor GRC, SoD management is fully automated.“Infor GRC provides a standard set of rule books with our Infor CloudSuite to automatically generate any SoD violations for us to review, as well as what-if analysis to test different role or permission scenarios. All the risks are laid out, removing the need to do negative testing. Now, we only spend one or two hours with the external auditors, which is a huge savings on our side.”- Sandy Frantom, Director of Accounting.

Global specialty vehicle manufacturer reduces auditing costs by 90% with Infor Governance, Risk, and Compliance

Infor Certification Manager replaces partial user access reviews

Infor GRC Certification Manager solved a major challenge in conducting annual user access reviews because it a streamlined process that makes it easy for every manager in the company to verify if their people have the right user access.

“Before we had certification manager, we did not have a tool to review 100% of our users. We would complete reviews manually by connecting with certain managers if we made an organizational change and high-risk areas to prepare for audits.”- Frantom.

Infor GRC Certification Manager kicks off a user review process and is finished in a two-week period. Each manager is responsible to review and sign off on user roles and responsibilities that they have in the system. The Infor GRC dashboard tracks each manager’s progress and sends reminder notifications to ensure timely completion of review. Once completed, the CIO reviews and signs off so it can be given to the external auditors.

“With Infor GRC Certification Manager, I can see who has completed the review and who hasn’t. It sends reminders automatically to people who have not completed the review and can also escalate to their manager if we're getting close to the deadline. Previously we spent weeks to prepare for audits and now we do a quick, daily check in with the dashboard to see where we are in the process.”- Frantom

Global specialty vehicle manufacturer reduces auditing costs by 90% with Infor Governance, Risk, and Compliance

Lowering security risk and cost with Infor GRC

“Infor GRC has transformed my daily tasks. Instead of handling numerous manual steps, I can now rely on dashboards that provide answers in minutes, saving hours of gathering information and tracking down people to make corrections.”-Frantom

With the deployment of two modules, Authorization Insight and Certification Manager, Infor GRC is lowering risk and cost at Miller Industries:

  • Authorization Insight for fast and accurate mitigation and auditing:
    • 93% productivity improvement and 672 hours saved annually
    • 90% reduction in auditing costs related to access testing
  • Certification Manager for easy user access review and completion:
    • 100% user access reviews
    • 98% productivity improvement, 105 hours saved annually

Infor GRC is an integrated service with Infor CloudSuite to easily manage and scale as the ERP footprint expands at Miller Industries. “As we continue to roll out Infor CloudSuite to new locations, Infor GRC operates smoothly in the background, allowing us to quickly assign roles and give users access to a test environment. This enables them to carry out necessary testing, and when transitioning to the production environment, there’s minimal risk of disruption due to authorizations or access issues.”- Whitmire.

Global specialty vehicle manufacturer reduces auditing costs by 90% with Infor Governance, Risk, and Compliance

Laying a foundation for the future with ease of knowledge transfer

“Infor GRC has greatly improved the efficiency of our access and controls monitoring. It has reduced costs and provided our executive team with confidence that proper oversight is in place. The system’s knowledge is easily transferable to future users, ensuring long-term benefits for years to come.”- Whitmire

Miller Industries partnered with New River Systems for a successful implementation of Infor GRC. An enormous benefit of the relationship was that there was a focus on transfer of knowledge to Miller Industries so that they are empowered to build out more functionality and maintain the system themselves. Being able to transfer knowledge easily gives Whitmire confidence that Infor GRC can support the business as it transitions from generation to generation.

To learn more about Infor GRC, visit https://developer.infor.com/components/governance-risk-and-compliance/