Enterprise · SAP security

Making SAP access easier to trust.

Too many people had access they no longer needed. Over three years, we helped an enterprise team untangle SAP roles, reduce conflicting permissions and build a routine for keeping access under control.

See what changed

The change, in numbers

Fewer conflicts. Clearer control.

2022–2024
Before and after the engagement

39%

Fewer potential access conflicts

1,973 1,194 before and after

17%

Fewer recorded access violations

418 346 before and after

See the full results breakdown
Measures tracked across the engagement
MeasureBeforeAfterReduction
Potential access conflicts1,9731,19439%
Recorded access violations41834617%
Vendor master & vendor invoices160498%
Payments & vendor master87495%
Posting periods & journal entries632659%
Credit management & sales orders925145%

Figures reported in the engagement summary are based on SAP GRC extracts covering 19 segregation-of-duties rules across Finance, Procurement and Sales, tracked from 2022 to 2024. Reductions are rounded to the nearest whole percent. These are counts of conflicts, not counts of people or monetary losses.

When access grows faster than oversight

SAP roles had accumulated as the business changed. New requests were approved, permissions overlapped, and there was no consistent process for deciding what should stay. Business users could end up with combinations of access that should have been kept separate.

This is a segregation-of-duties problem: one person can carry out steps that should require another person’s involvement. For example, being able to change a vendor’s details and process payments creates a control risk, even when nobody has misused that access.

The team also faced recurring access-control audit findings. Fixing individual permissions would help, but without clear ownership and regular reviews, the same problems could return.

Start with the people behind the roles

We began by mapping the authorization landscape and working with business process owners to understand which access people actually needed. The goal was to reduce risk without leaving teams unable to do their jobs.

That meant agreeing on naming conventions, documenting role designs and giving each role family a business owner. Access requests and role changes gained a defined review process. Periodic user access reviews gave owners a way to spot permissions that no longer belonged.

We then worked through conflicts in order of risk. Some roles could be split or redesigned. Where a conflicting combination could not be removed, the team put compensating controls in place and documented the accepted risk. Those exceptions became something to manage and review, rather than something to lose track of.

Three years of steady work

Year one: understand and put foundations in place

We assessed the existing risks, began cleaning up roles and established the governance framework. Least privilege, role-based access and consistent naming gave the team shared rules for future decisions.

Year two: change the roles and the routine

The focus moved to critical and high-risk conflicts. We introduced a layered role model, separating base access from additional responsibilities, and supported access lifecycle automation. The first user access review cycle and audit remediation work helped turn the design into day-to-day practice.

Year three: make the improvements last

We consolidated the role catalogue, introduced preventive conflict checks and refined the controls for exceptions. Monitoring and policy updates kept governance aligned with changes in the business.

Across the engagement, the team maintained role documentation, conflict reports, review sign-offs and exception logs as audit evidence. Preparing for an audit became part of the ongoing work.

Less risk, with the remaining work in view

Potential conflicts fell from 1,973 to 1,194, a reduction of 39%. Recorded violations fell from 418 to 346, down 17%. The strongest reductions were in two high-risk procurement combinations: vendor master access paired with vendor invoices, and payments paired with vendor master access. Each ended at four potential conflicts.

Those measures tell different stories. A potential conflict means someone has the permissions to perform conflicting activities. A recorded violation means the conflicting activities were identified in the activity data. Neither measure, on its own, establishes fraud or financial loss.

The work did not remove every conflict. Remaining risks included combinations covered by compensating controls, with continued monitoring and review. The useful outcome was a smaller risk exposure and a clearer process for managing what remained.

What the partnership left behind

Alongside the reductions, the client gained named role owners, a maintained role catalogue, recurring access reviews and a shared evidence library. New requests could be assessed against agreed rules instead of becoming another exception nobody owned.

That is why this work benefited from a sustained partnership. Each review informed the next change. Each change became part of the governance routine. The team had a way to keep improving access control as the business moved on.

Let’s talk about your SAP landscape

Access should make sense. For your team and your auditors.

Bring the roles, conflicts or audit questions that keep coming back. We’ll help you work out where to start.

Book a diagnosis call
← All client stories