US · guidance
BOP Program Statement 8052.04 § 2
RESPONSIBILITIES
This section defines the roles and responsibilities of the following positions within FPI:
3
8052.04
P8052.XX 3/19/2026
04/16/2025 PROPERTY OF US GOVERNMENT 11
a. Business Process Owners (BPO). The functional personnel responsible for protecting the
integrity of the information and processes supported by the FPI financial information system.
BPOs or designees are responsible for:
■ Developing and approving written mitigating controls for segregation of duty (SOD) risk
identified by the Governance, Risk, and Compliance (GRC) tool.
■ Approving newly created or changes to existing roles in their functional area.
■ Reviewing and approving the re-certification of the functional roles assigned to users.
b. Deputy Assistant Director (DAD). The person responsible when mutual agreement cannot
be reached by the granting BPO and requestor, the DAD makes the final decision based on all
the information given to them to grant or deny the request.
c. Enterprise Resource Planning (ERP) Help Desk. ERP Help Desk personnel are
responsible for monitoring, directing, and developing FPI financial information system access.
This includes but is not limited to:
■ Role creation, maintenance, and deletions based upon BPO approval.
■ Maintaining license controls for users, and providing ad hoc license reports to all
business areas, as well as the final yearly license report to SAP.
■ Preparing the annual recertification documents for user accounts.
■ Reviewing requests for new FPI financial information system users and modifications to
existing accounts, coordinating the approval process of all stakeholders, and issuing
direction to the SAP User Administrator in making the actual user account change.
d. ERP Business Process Analysts. ERP duties are to help administrators define the technical
rules for each business area for approved risk conditions and recommend alternatives to
eliminate SOD risks in roles and user assignments.
e. Internal Control and Compliance Group (ICCG). ICCG performs risk assessments and
mitigating control reviews on a regular basis to identify new risks, performs periodic testing of
rules and mitigating controls, and acts as a liaison with external auditors.
f. GRC Administrator. The GRC Administrator maintains the GRC tool. This includes but is
not limited to the following functions:
■ Maintaining and managing the GRC tool.
■ Primary gatekeeper of SOD compliance and reporting among roles and user accounts.
■ Maintaining GRC mitigating control (MC) documentation.
■ Maintaining GRC reports or monitoring tools to identify SOD conflicts and user access.
g. SAP Security Administrator. The SAP Security Administrator maintains security
3
8052.04
P8052.XX 3/19/2026
04/16/2025 PROPERTY OF US GOVERNMENT 22
procedures for the SAP environment. This includes but is not limited to:
■ Developing SAP security procedures and monitoring methods.
■ Using the GRC tool to monitor the SAP environment for SOD compliance and reporting
among roles and user accounts.
■ Using the GRC tool to monitor MCs.
■ Reviewing the role development process and advising about security concerns.
h. Information System Security Officer (ISSO). This is a Management Information Systems
Branch (MISB) position and is responsible for security policy compliance throughout FPI. They
perform audits and generate reports on system security violations to the Department of Justice
(DOJ) and FPI management. This position also tracks violations and system security changes.
i. SAP User Administrator. This position is responsible for creating and maintaining user
accounts. They are typically the System Administrator, but the duties can be assigned to other
positions or automated systems.
j. License Owners (LO). Individuals or entities who have authority over the SAP access
licenses for a specific business process or business group (e.g., branch chiefs).
k. Chief Information Officer (CIO). The individual responsible for all information system
matters. The CIO is responsible for System Administrators. ERP is also a section within MISB.
l. Chief Financial Officer (CFO). The individual with ultimate responsibility for financial
policy and procedure.
m. Branch Chief (BC) or General Manager (GM). Individual responsible for a support branch
or business unit within FPI. The BC or GM (or designee) is responsible for user license approval
for new users in their unit.
n. Chief Enterprise Resource Planning (CERP). The individual with ultimate responsibility
for all aspects of FPI financial information system authorizations. When a decision made for a
role or the abuse of role privileges introduces a threat to the security of the FPI financial
information system environment, the CERP has the authority to overrule the decision to
eliminate or reduce the threat.
History
PS 8052.04 dated 2026-03-19
Provenance
- Source
- bop.gov
- Retrieved
- 2026-09-20
- Edition
- bop-ps-2026-09-20
- Content hash
85d51063bd5e2cdca99c2e7e92cf12da0d1cc5b6a3163dbffc1325d990c9e27b
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.