SAP SoD remediation

Your GRC finds the conflicts. We close them.

Know which SoD conflicts actually happened, and exactly how to close them. Start with a fixed-fee, four-week Blueprint that shows what to fix. Then we fix it, and keep it fixed.

From reported to resolved

Example figures for a mid-size S/4HANA landscape.

Illustrative
Conflicts your ruleset reports4,812
100%
In roles people actually use1,236
26%
Executed in the last 12 months87
6%
Critical, close in the first 30 days12
3%

Your Blueprint starts with your real numbers.

The risk

Employees with SAP access that lets them create a supplier and pay it, or change and approve their own access. Often already flagged by your auditor.

The outcome

The finding closed before your next audit, with evidence your auditor accepts, and a fix that stops it coming back.

The approach

Four weeks to a tested plan. Fixed fee per phase, approved one phase at a time, with a clean stop after each.

Why now

Why it matters now

  • Fraud exposure

    One person able to set up a supplier and release its payment is the most common route to internal fraud.

  • Your audit opinion

    A repeat finding can escalate to a significant deficiency or material weakness.

  • Cost and attention

    More audit testing, higher fees, and an Audit Committee conversation every year.

When to call us

  • An open audit finding with a deadline
  • A remediation project that has stalled or keeps getting reopened
  • An S/4HANA migration that is rebuilding your roles
  • A new or tougher auditor asking for evidence you can't easily produce
How we close your findings

Six steps, from real exposure to audit evidence.

StepWhat we doWhat you get
1Find the real exposure
We check who actually executed conflicting transactions in the last 12 months, not just who could.A short list, not thousands of lines. Real risk fixed first; unused access removed with no business impact.
2Trace the root cause
We trace each conflict back to the roles that create it, across all connected systems.Fixes at role level, not user by user.
3Design and test the fix
We redesign the conflicting roles and test every change before it reaches production.Conflicts removed without breaking anyone's job.
4Clean up mitigating controls
We keep, fix or retire each control, and give each one a named owner and evidence.Fewer controls, and ones your auditor can actually test.
5Stop them coming back
We fix the access request process so new conflicts are blocked before they are granted.The clean-up holds, instead of eroding within months.
6Prove it to audit
We document the method, before-and-after results and a plain-language brief for each risk.The evidence to close the finding, signed off by owners who understand it.

What we need from you: read-only system access or a file extract, one sponsor, and about two hours from each process owner.

What the Blueprint gives you

Eight deliverables, reviewed and signed by a senior practitioner.

Executed-conflict baseline

The conflicts actually executed in the last 12 months, ranked by risk.

Root-cause map

Each conflict traced to the roles that create it across your connected systems.

Ranked action list

What to fix first, second and third, with effort and business impact noted.

Tested role changes

Redesigned roles validated before they touch production, so nothing breaks.

Mitigation clean-up

Each compensating control kept, fixed or retired, with a named owner.

Plain-language risk briefs

One page per risk, written so the Audit Committee can read it.

90-day roadmap

A sequenced plan with owners and target dates for the first ninety days.

Leadership session

A walkthrough for your leadership team and audit lead before sign-off.

A page from the action list

Example rows

#RiskConflicting accessExecutedRoot causeActionOwnerTarget
CriticalCreate vendor and pay vendorXK01 + F11014 usersAP clerk role includes vendor masterSplit roleHead of APWeek 3
CriticalChange vendor bank details and post invoiceFK02 + MIRO6 usersVendor master and posting combinedRemove FK02 from roleHead of APWeek 3
HighMaintain customer and post credit memoXD02 + FB753 usersCustomer master and posting combinedSplit roleHead of ARWeek 5
MediumCreate and release purchase orderME21N + ME29N0 usersCreation and approval in one roleRemove on grantHead of ProcurementWeek 6

Scroll sideways on smaller screens to see every column.

Pricing

One path. Three phases. A clean exit after each.

1
Start here

Remediation Blueprint

4 weeks

€20K to €45K fixed fee

Start here

2

Remediation Delivery

8 to 12 weeks

Fixed fee, quoted after Phase 1

Available after Phase 1

3

Stay Clean

Monthly

Monthly fee, quoted after Phase 1

Cancel with 30 days' notice.

Available after Phase 1

How payment works: each phase is a fixed fee agreed before it starts, invoiced 50% upfront and 50% on delivery. The Blueprint range covers one to three SAP systems; larger landscapes are scoped individually.

Who does the work

Senior SAP Security and GRC specialists only.

14+ years of SAP access control and audit work across pharmaceuticals, insurance, retail, chemicals and transport, in the UK, the Netherlands, Belgium and Portugal, on every SAP GRC release from 5.3 to 12.

One accountable lead

A single senior practitioner owns your engagement from start to finish.

No juniors learning on your system

Every step is done by experienced SAP security and GRC specialists.

One method, every time

The same tested approach on every engagement, refined across years of audit work.

FAQ

Questions, answered.

Next step

Book a free 30-minute assessment.

We look at your landscape, your open findings and your audit date, and tell you honestly whether a Blueprint is the right first step.

  • Your landscape and connected systems
  • Open findings and deadlines
  • An honest view on whether a Blueprint fits
Book your assessment
Encrypted, no public cloud, NDA and DPA before any data is shared.