← All modules
smartSoD icon

smartSoD

A ready library of 100+ SoD risks and 50+ critical access - from GRC experts.

This module offers a comprehensive library for handling Segregation of Duties (SoD) risks and critical access to the system. Built on years of experience and insights from our clients, it helps streamline projects focused on improving or redesigning user authorizations. With more than 100 SoD risks and 50+ critical accesses, the library shortens implementation time and supports both standard and custom transactions.

auto_awesome Our AI vision (in development)

AI agents in smartSoD

3 agents handle the routine work in this module and escalate only what needs a human. Each agent has its own autonomy dial - your governance officer chooses how much the agent does and where humans stay in the loop.

shield_lock

Your governance officer owns the dial

Per agent, per environment, per risk level - tighten or loosen autonomy without redeploying code or filing engineering tickets. The agent never decides its own permission level. Business rules decide, and your team owns the rules.

Off
No AI
Suggest
AI advises
Approve
Human gate
Auto
Rules-governed
Agent 1 of 3 . Real-time SoD Risk Monitoring

AI Real-time SoD Risk Monitoring

The agent watches every role and assignment change. New SoD conflicts surface within minutes instead of waiting for the monthly report cycle.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
Live SoD risk feed
smartSoD
Open risks
23
New today
3
Critical
2
Mitigated
156
NEW . 4 min ago
RISK-FI-04 . Post and Approve invoice
Triggered by role change on Z_FI_SUPER (added F-04). 12 users now in conflict.
NEW . 47 min ago
RISK-MM-02 . Vendor and Payment
New assignment: T. Kowalski received SAP_MM_VENDOR (already had SAP_FI_PAY).
2h ago
RISK-HR-01 . Hire and Pay
Detected . 2 users flagged . mitigation MC-031 already in place.
3h ago
RISK-SD-03 . Quote and Discount
Auto-resolved by removing SAP_SD_DISCOUNT_OVERRIDE from 3 users.

Illustrative mockup from the smartSoD risk feed. NEW badges mark conflicts detected since the page was last viewed.

What you see
  • looks_oneLive dashboard with open / new / critical / mitigated counts.
  • looks_twoNEW badges on conflicts detected since your last view.
  • looks_3Trigger context: which role change or assignment caused it.
  • looks_4Auto-resolution for trivial cases (e.g. role removed before damage).
trending_up

Zero-day detection beats monthly reports

Conflicts that used to live in your system for weeks are caught within minutes. Less time to incident, smaller exposure window.

Agent 2 of 3 . Mitigation Designer

AI Mitigation Designer

Agent proposes concrete controls and mitigations for accepted SoD risks, drawing from a best-practice library. Each option includes effort estimate and expected residual risk.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
Risk RISK-FI-04 - mitigation designer
smartSoD
Post and Approve invoice
12 users . 4 roles . accepted (residual risk . needs mitigation)
auto_awesome AI-suggested mitigations
MC-021A . Manual 4-eyes on amounts > 50k RECOMMENDED

Existing control MC-021 covers >100k. Lowering threshold to 50k closes the gap. Estimated effort: 2h policy update + workflow tweak.

MC-049 . Monthly review of postings by F-04 users ALT

Detective control - reviewer compares postings vs. approvals. Higher effort, weaker signal than preventive MC-021A.

MC-072 . Block F-04 in critical company codes ALT

Strongest preventive option. Trade-off: 3 users lose legitimate approval capability and need workaround.

Illustrative mockup from the smartSoD risk detail. AI-suggested mitigations appear ranked with effort and effect; user adopts or chooses an alternative.

What you see
  • looks_oneAI-suggested mitigations ranked by effort and effect.
  • looks_twoExisting-control awareness - extends MC-021 instead of inventing MC-021A from scratch.
  • looks_3Each option shows: effort estimate, expected residual risk, trade-offs.
  • looks_4Risk owner picks; selection auto-fills the mitigation register.
trending_up

Findings closed faster, with better remediation

External auditors get a concrete remediation plan, not a generic 'consider implementing a control' note. Findings close in days instead of audit cycles.

Agent 3 of 3 . Conflict Resolution Advisor

AI Conflict Resolution Advisor

Agent proposes concrete fixes for SoD conflicts: split a role, remove a specific TX, apply a compensating control. Most cases have an obvious BEST option; humans decide the nuanced ones.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
Conflict RISK-MM-02 - resolution options
smartSoD
Vendor and Payment - T. Kowalski
Holds SAP_MM_VENDOR (FK01/FK02) + SAP_FI_PAY (F-58/F110). Single user could create a fraudulent vendor and pay it.
construction AI-proposed fixes (most to least preferred)
Fix 1: Remove SAP_FI_PAY BEST

User has not run F-58 or F110 in 6 months. Payment is handled by AP team. Removing F-58 access closes the conflict with no business impact.

Fix 2: Split SAP_MM_VENDOR ALT

Create SAP_MM_VENDOR_DISPLAY (read-only) and keep SAP_MM_VENDOR_EDIT for a smaller group. Higher refactor effort.

Fix 3: Apply MC-018 (4-eyes payment release) DETECTIVE

Existing manual control. Keeps both roles, requires monthly evidence. Weakest of the three.

Illustrative mockup from the smartSoD conflict detail. Agent proposes ranked fixes - role removal, split or compensating control - with effort and impact.

What you see
  • looks_oneConflict explained in human-readable business terms.
  • looks_twoAI-proposed fixes ranked BEST / ALT / DETECTIVE.
  • looks_3Each option shows trade-offs, who loses what, and effort.
  • looks_4Risk owner can apply, send to role owner, or rewrite manually.
trending_up

From 'add a control' to a specific remediation

Conflict tickets carry actionable proposals instead of generic action items. Role owners spend time deciding, not designing options.

Key features

smartSoD · Matrix & Risk monitoring
auto_awesome
Agent detected 3 new critical conflicts in the last 24h
Triggered by role change Z_FI_AP_POST · auto-mitigations proposed
3 CRITICAL
R-FI-001 CRITICAL Posting + document approval
FI · General ledger · PL-HQ
auto_awesome Agent suggests mitigation

Add 4-eyes approval rule on transaction FB02 for users in role FF_FI_01. Similar mitigation accepted 8 times in last 30 days.

R-MM-004 HIGH Order creation + invoice approval + mitigation ready
R-HR-007 CRITICAL Personal data update + payroll list + mitigation ready

Illustrative mockup. The SoD Monitoring Agent watches every role change in real time and proposes mitigations drawn from a best-practice library.

What you see
  • looks_oneReal-time alert when a role change introduces new SoD conflicts.
  • looks_twoAuto-suggested mitigations with reasoning (4-eyes, scope reduction, compensating control).
  • looks_3Risk owner can Accept or Edit the proposal - every decision logged.
trending_up

Zero-day detection

Catch new conflicts the moment they appear, not on the next monthly report.

check_circle

100+ SoD risks out-of-the-box

Ready library covering P2P, OTC, R2R, HR, Treasury - start the project, not from a blank page.

check_circle

50+ critical access entries

Predefined list of high-risk transactions (SAP_ALL, SE16, SM30, debugger) with context on why they are critical.

check_circle

Standard & custom transactions

Mapping covers both standard SAP transactions and customer Z-transactions - easy to extend.

check_circle

Mapping to processes

Every risk described in business-process context - intuitive for auditors and process owners.

check_circle

Mitigating controls

For each risk the library suggests mitigating controls - what to do when separation is not feasible.

check_circle

Compliance baseline

Library based on Big4, ITGC, COSO - starting point for organizational compliance documentation.

Typical use cases

FAQ

Frequently asked questions about smartSoD

smartSoD vs SAP GRC Access Control SoD - what's different? expand_more

smartSoD covers the same Segregation of Duties analytics as SAP GRC AC ARA but adds three key capabilities: (1) 125+ pre-built SoD risks across ECC and S/4HANA out of the box (vs SAP GRC AC requiring custom ruleset), (2) AI-suggested compensating controls based on patterns from 15 enterprise customer landscapes, (3) cross-system SoD covering SAP + non-SAP via XML adapter (SAP GRC AC is SAP-only). Pricing: from €15K/year vs ~€200K/year for SAP GRC AC.

Does smartSoD work on SAP S/4HANA and ECC? expand_more

Yes. smartSoD ships with 125+ pre-built SoD risks calibrated for both SAP ECC 6.0 (traditional GUI transactions) and S/4HANA (Fiori apps + new transaction codes). The ruleset is maintained against actual SAP transaction changes - when SAP changes a transaction code in a new release, the SoD rule updates automatically. For S/4HANA-specific risks (e.g., new Fiori-based payment workflows), dedicated rule additions are part of the standard release cadence.

How do you handle compensating controls in smartSoD? expand_more

smartSoD supports the full compensating-control workflow: (1) identification of users with toxic SoD combinations, (2) compensating control definition (e.g., quarterly review by independent reviewer, dual-approval workflow, exception monitoring), (3) periodic effectiveness review (the control is actually operating). We published a detailed case study on mitigating controls effectiveness.

What's the implementation timeline for smartSoD? expand_more

Standard SoD deployment: 2-4 weeks from kick-off to first risk report. Tasks: SAP role catalogue ingestion (week 1), SoD ruleset configuration and tuning (week 2), risk classification with business stakeholders (week 3), first quarterly review report (week 4). The Professional plan (€30K/year) includes implementation services. The Free plan covers up to 25 SAP users for a no-risk pilot.

Can smartSoD analyze non-SAP systems too? expand_more

Yes - via the universal XML adapter pattern. smartSoD reads user/permission/risk data from any system that can export to the documented XSD schema. We have customers running smartSoD across SAP + billing + Teradata DWH + custom apps in one consolidated SoD analysis. Read the Beyond SAP case study covering 8 non-SAP systems.

Do external auditors accept smartSoD risk reports? expand_more

Yes. smartSoD has been accepted by Big 4 auditors (EY, KPMG, Deloitte, PwC) in multiple financial audits of publicly-listed groups. The audit trail includes: SoD rule version, user-role-permission combinations identified, compensating controls in place, reviewer decisions with timestamps. All exports are in CSV/XML/PDF formats acceptable for external auditor working papers.

How does smartSoD compare to Pathlock and Xiting for SoD analytics? expand_more

All three handle SoD analytics, but each fits different scenarios. Pathlock is the larger US-based vendor with broader feature checklist and US pricing (typically higher than smartSoD). Xiting focuses on SAP role redesign with SoD as a subset. smartSoD is the European choice for organizations prioritizing EU data residency, transparent pricing (€15K-€60K/year), AI-first architecture. See dedicated vs Pathlock and vs Xiting pages.

Can I test smartSoD without commitment? expand_more

Yes: the interactive demo is accessible without signup. The Free plan covers up to 25 SAP users with basic SoD analytics (25 risk presets, smartReport) - perfect for a no-risk pilot or small team. Upgrade to Professional (€30K/year, 800 users) or Enterprise (custom) when ready to scale.

Ready to see it live?

Try the interactive UX preview - no signup, no credit card.