This document provides an overview of auditing SAP GRC (Governance, Risk, and Compliance) at The Coca-Cola Company. It introduces Sean Campbell and Jay Gohil, who are IT auditors at Coca-Cola, and discusses SAP security, GRC modules, and key areas of focus for auditing SAP GRC including governance, configuration, change management, access risk analysis, and emergency access management. Common audit issues with SAP GRC implementations are also reviewed such as ruleset and risk changes, mitigating controls, business process changes, and firefighter access management.