Your GRC finds the conflicts. We close them.
Know which SoD conflicts actually happened, and exactly how to close them. Start with a fixed-fee, four-week Blueprint that shows what to fix. Then we fix it, and keep it fixed.
From reported to resolved
Example figures for a mid-size S/4HANA landscape.
Your Blueprint starts with your real numbers.
Employees with SAP access that lets them create a supplier and pay it, or change and approve their own access. Often already flagged by your auditor.
The finding closed before your next audit, with evidence your auditor accepts, and a fix that stops it coming back.
Four weeks to a tested plan. Fixed fee per phase, approved one phase at a time, with a clean stop after each.
Why it matters now
Fraud exposure
One person able to set up a supplier and release its payment is the most common route to internal fraud.
Your audit opinion
A repeat finding can escalate to a significant deficiency or material weakness.
Cost and attention
More audit testing, higher fees, and an Audit Committee conversation every year.
When to call us
- An open audit finding with a deadline
- A remediation project that has stalled or keeps getting reopened
- An S/4HANA migration that is rebuilding your roles
- A new or tougher auditor asking for evidence you can't easily produce
Six steps, from real exposure to audit evidence.
| Step | What we do | What you get |
|---|---|---|
1Find the real exposure | We check who actually executed conflicting transactions in the last 12 months, not just who could. | A short list, not thousands of lines. Real risk fixed first; unused access removed with no business impact. |
2Trace the root cause | We trace each conflict back to the roles that create it, across all connected systems. | Fixes at role level, not user by user. |
3Design and test the fix | We redesign the conflicting roles and test every change before it reaches production. | Conflicts removed without breaking anyone's job. |
4Clean up mitigating controls | We keep, fix or retire each control, and give each one a named owner and evidence. | Fewer controls, and ones your auditor can actually test. |
5Stop them coming back | We fix the access request process so new conflicts are blocked before they are granted. | The clean-up holds, instead of eroding within months. |
6Prove it to audit | We document the method, before-and-after results and a plain-language brief for each risk. | The evidence to close the finding, signed off by owners who understand it. |
What we need from you: read-only system access or a file extract, one sponsor, and about two hours from each process owner.
Eight deliverables, reviewed and signed by a senior practitioner.
Executed-conflict baseline
The conflicts actually executed in the last 12 months, ranked by risk.
Root-cause map
Each conflict traced to the roles that create it across your connected systems.
Ranked action list
What to fix first, second and third, with effort and business impact noted.
Tested role changes
Redesigned roles validated before they touch production, so nothing breaks.
Mitigation clean-up
Each compensating control kept, fixed or retired, with a named owner.
Plain-language risk briefs
One page per risk, written so the Audit Committee can read it.
90-day roadmap
A sequenced plan with owners and target dates for the first ninety days.
Leadership session
A walkthrough for your leadership team and audit lead before sign-off.
A page from the action list
Example rows
| # | Risk | Conflicting access | Executed | Root cause | Action | Owner | Target |
|---|---|---|---|---|---|---|---|
| Critical | Create vendor and pay vendor | XK01 + F110 | 14 users | AP clerk role includes vendor master | Split role | Head of AP | Week 3 |
| Critical | Change vendor bank details and post invoice | FK02 + MIRO | 6 users | Vendor master and posting combined | Remove FK02 from role | Head of AP | Week 3 |
| High | Maintain customer and post credit memo | XD02 + FB75 | 3 users | Customer master and posting combined | Split role | Head of AR | Week 5 |
| Medium | Create and release purchase order | ME21N + ME29N | 0 users | Creation and approval in one role | Remove on grant | Head of Procurement | Week 6 |
Scroll sideways on smaller screens to see every column.
One path. Three phases. A clean exit after each.
Remediation Delivery
Fixed fee, quoted after Phase 1
Available after Phase 1
Stay Clean
Monthly fee, quoted after Phase 1
Cancel with 30 days' notice.
Available after Phase 1
How payment works: each phase is a fixed fee agreed before it starts, invoiced 50% upfront and 50% on delivery. The Blueprint range covers one to three SAP systems; larger landscapes are scoped individually.
Senior SAP Security and GRC specialists only.
14+ years of SAP access control and audit work across pharmaceuticals, insurance, retail, chemicals and transport, in the UK, the Netherlands, Belgium and Portugal, on every SAP GRC release from 5.3 to 12.
One accountable lead
A single senior practitioner owns your engagement from start to finish.
No juniors learning on your system
Every step is done by experienced SAP security and GRC specialists.
One method, every time
The same tested approach on every engagement, refined across years of audit work.
Questions, answered.
Book a free 30-minute assessment.
We look at your landscape, your open findings and your audit date, and tell you honestly whether a Blueprint is the right first step.
- Your landscape and connected systems
- Open findings and deadlines
- An honest view on whether a Blueprint fits