A ready library of 100+ SoD risks and 50+ critical access - from GRC experts.
This module offers a comprehensive library for handling Segregation of Duties (SoD) risks and critical access to the system. Built on years of experience and insights from our clients, it helps streamline projects focused on improving or redesigning user authorizations. With more than 100 SoD risks and 50+ critical accesses, the library shortens implementation time and supports both standard and custom transactions.
3 agents handle the routine work in this module and escalate only what needs a human. Each agent has its own autonomy dial - your governance officer chooses how much the agent does and where humans stay in the loop.
Per agent, per environment, per risk level - tighten or loosen autonomy without redeploying code or filing engineering tickets. The agent never decides its own permission level. Business rules decide, and your team owns the rules.
The agent watches every role and assignment change. New SoD conflicts surface within minutes instead of waiting for the monthly report cycle.
Illustrative mockup from the smartSoD risk feed. NEW badges mark conflicts detected since the page was last viewed.
Conflicts that used to live in your system for weeks are caught within minutes. Less time to incident, smaller exposure window.
Agent proposes concrete controls and mitigations for accepted SoD risks, drawing from a best-practice library. Each option includes effort estimate and expected residual risk.
Existing control MC-021 covers >100k. Lowering threshold to 50k closes the gap. Estimated effort: 2h policy update + workflow tweak.
Detective control - reviewer compares postings vs. approvals. Higher effort, weaker signal than preventive MC-021A.
Strongest preventive option. Trade-off: 3 users lose legitimate approval capability and need workaround.
Illustrative mockup from the smartSoD risk detail. AI-suggested mitigations appear ranked with effort and effect; user adopts or chooses an alternative.
External auditors get a concrete remediation plan, not a generic 'consider implementing a control' note. Findings close in days instead of audit cycles.
Agent proposes concrete fixes for SoD conflicts: split a role, remove a specific TX, apply a compensating control. Most cases have an obvious BEST option; humans decide the nuanced ones.
User has not run F-58 or F110 in 6 months. Payment is handled by AP team. Removing F-58 access closes the conflict with no business impact.
Create SAP_MM_VENDOR_DISPLAY (read-only) and keep SAP_MM_VENDOR_EDIT for a smaller group. Higher refactor effort.
Existing manual control. Keeps both roles, requires monthly evidence. Weakest of the three.
Illustrative mockup from the smartSoD conflict detail. Agent proposes ranked fixes - role removal, split or compensating control - with effort and impact.
Conflict tickets carry actionable proposals instead of generic action items. Role owners spend time deciding, not designing options.
Add 4-eyes approval rule on transaction FB02 for users in role FF_FI_01. Similar mitigation accepted 8 times in last 30 days.
Illustrative mockup. The SoD Monitoring Agent watches every role change in real time and proposes mitigations drawn from a best-practice library.
Catch new conflicts the moment they appear, not on the next monthly report.
Ready library covering P2P, OTC, R2R, HR, Treasury - start the project, not from a blank page.
Predefined list of high-risk transactions (SAP_ALL, SE16, SM30, debugger) with context on why they are critical.
Mapping covers both standard SAP transactions and customer Z-transactions - easy to extend.
Every risk described in business-process context - intuitive for auditors and process owners.
For each risk the library suggests mitigating controls - what to do when separation is not feasible.
Library based on Big4, ITGC, COSO - starting point for organizational compliance documentation.
smartSoD covers the same Segregation of Duties analytics as SAP GRC AC ARA but adds three key capabilities: (1) 125+ pre-built SoD risks across ECC and S/4HANA out of the box (vs SAP GRC AC requiring custom ruleset), (2) AI-suggested compensating controls based on patterns from 15 enterprise customer landscapes, (3) cross-system SoD covering SAP + non-SAP via XML adapter (SAP GRC AC is SAP-only). Pricing: from €15K/year vs ~€200K/year for SAP GRC AC.
Yes. smartSoD ships with 125+ pre-built SoD risks calibrated for both SAP ECC 6.0 (traditional GUI transactions) and S/4HANA (Fiori apps + new transaction codes). The ruleset is maintained against actual SAP transaction changes - when SAP changes a transaction code in a new release, the SoD rule updates automatically. For S/4HANA-specific risks (e.g., new Fiori-based payment workflows), dedicated rule additions are part of the standard release cadence.
smartSoD supports the full compensating-control workflow: (1) identification of users with toxic SoD combinations, (2) compensating control definition (e.g., quarterly review by independent reviewer, dual-approval workflow, exception monitoring), (3) periodic effectiveness review (the control is actually operating). We published a detailed case study on mitigating controls effectiveness.
Standard SoD deployment: 2-4 weeks from kick-off to first risk report. Tasks: SAP role catalogue ingestion (week 1), SoD ruleset configuration and tuning (week 2), risk classification with business stakeholders (week 3), first quarterly review report (week 4). The Professional plan (€30K/year) includes implementation services. The Free plan covers up to 25 SAP users for a no-risk pilot.
Yes - via the universal XML adapter pattern. smartSoD reads user/permission/risk data from any system that can export to the documented XSD schema. We have customers running smartSoD across SAP + billing + Teradata DWH + custom apps in one consolidated SoD analysis. Read the Beyond SAP case study covering 8 non-SAP systems.
Yes. smartSoD has been accepted by Big 4 auditors (EY, KPMG, Deloitte, PwC) in multiple financial audits of publicly-listed groups. The audit trail includes: SoD rule version, user-role-permission combinations identified, compensating controls in place, reviewer decisions with timestamps. All exports are in CSV/XML/PDF formats acceptable for external auditor working papers.
All three handle SoD analytics, but each fits different scenarios. Pathlock is the larger US-based vendor with broader feature checklist and US pricing (typically higher than smartSoD). Xiting focuses on SAP role redesign with SoD as a subset. smartSoD is the European choice for organizations prioritizing EU data residency, transparent pricing (€15K-€60K/year), AI-first architecture. See dedicated vs Pathlock and vs Xiting pages.
Yes: the interactive demo is accessible without signup. The Free plan covers up to 25 SAP users with basic SoD analytics (25 risk presets, smartReport) - perfect for a no-risk pilot or small team. Upgrade to Professional (€30K/year, 800 users) or Enterprise (custom) when ready to scale.
Try the interactive UX preview - no signup, no credit card.