Bindinglaw

US · guidance

BOP Program Statement 8052.04 § 2

RESPONSIBILITIES

activein force · 2026-03-19 – presentact-effective-date

This section defines the roles and responsibilities of the following positions within FPI:

3

8052.04

P8052.XX 3/19/2026

04/16/2025 PROPERTY OF US GOVERNMENT 11

a. Business Process Owners (BPO). The functional personnel responsible for protecting the

integrity of the information and processes supported by the FPI financial information system.

BPOs or designees are responsible for:

■ Developing and approving written mitigating controls for segregation of duty (SOD) risk

identified by the Governance, Risk, and Compliance (GRC) tool.

■ Approving newly created or changes to existing roles in their functional area.

■ Reviewing and approving the re-certification of the functional roles assigned to users.

b. Deputy Assistant Director (DAD). The person responsible when mutual agreement cannot

be reached by the granting BPO and requestor, the DAD makes the final decision based on all

the information given to them to grant or deny the request.

c. Enterprise Resource Planning (ERP) Help Desk. ERP Help Desk personnel are

responsible for monitoring, directing, and developing FPI financial information system access.

This includes but is not limited to:

■ Role creation, maintenance, and deletions based upon BPO approval.

■ Maintaining license controls for users, and providing ad hoc license reports to all

business areas, as well as the final yearly license report to SAP.

■ Preparing the annual recertification documents for user accounts.

■ Reviewing requests for new FPI financial information system users and modifications to

existing accounts, coordinating the approval process of all stakeholders, and issuing

direction to the SAP User Administrator in making the actual user account change.

d. ERP Business Process Analysts. ERP duties are to help administrators define the technical

rules for each business area for approved risk conditions and recommend alternatives to

eliminate SOD risks in roles and user assignments.

e. Internal Control and Compliance Group (ICCG). ICCG performs risk assessments and

mitigating control reviews on a regular basis to identify new risks, performs periodic testing of

rules and mitigating controls, and acts as a liaison with external auditors.

f. GRC Administrator. The GRC Administrator maintains the GRC tool. This includes but is

not limited to the following functions:

■ Maintaining and managing the GRC tool.

■ Primary gatekeeper of SOD compliance and reporting among roles and user accounts.

■ Maintaining GRC mitigating control (MC) documentation.

■ Maintaining GRC reports or monitoring tools to identify SOD conflicts and user access.

g. SAP Security Administrator. The SAP Security Administrator maintains security

3

8052.04

P8052.XX 3/19/2026

04/16/2025 PROPERTY OF US GOVERNMENT 22

procedures for the SAP environment. This includes but is not limited to:

■ Developing SAP security procedures and monitoring methods.

■ Using the GRC tool to monitor the SAP environment for SOD compliance and reporting

among roles and user accounts.

■ Using the GRC tool to monitor MCs.

■ Reviewing the role development process and advising about security concerns.

h. Information System Security Officer (ISSO). This is a Management Information Systems

Branch (MISB) position and is responsible for security policy compliance throughout FPI. They

perform audits and generate reports on system security violations to the Department of Justice

(DOJ) and FPI management. This position also tracks violations and system security changes.

i. SAP User Administrator. This position is responsible for creating and maintaining user

accounts. They are typically the System Administrator, but the duties can be assigned to other

positions or automated systems.

j. License Owners (LO). Individuals or entities who have authority over the SAP access

licenses for a specific business process or business group (e.g., branch chiefs).

k. Chief Information Officer (CIO). The individual responsible for all information system

matters. The CIO is responsible for System Administrators. ERP is also a section within MISB.

l. Chief Financial Officer (CFO). The individual with ultimate responsibility for financial

policy and procedure.

m. Branch Chief (BC) or General Manager (GM). Individual responsible for a support branch

or business unit within FPI. The BC or GM (or designee) is responsible for user license approval

for new users in their unit.

n. Chief Enterprise Resource Planning (CERP). The individual with ultimate responsibility

for all aspects of FPI financial information system authorizations. When a decision made for a

role or the abuse of role privileges introduces a threat to the security of the FPI financial

information system environment, the CERP has the authority to overrule the decision to

eliminate or reduce the threat.

History

PS 8052.04 dated 2026-03-19

Provenance

Source
bop.gov
Retrieved
2026-09-20
Edition
bop-ps-2026-09-20
Content hash
85d51063bd5e2cdca99c2e7e92cf12da0d1cc5b6a3163dbffc1325d990c9e27b
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.