Review preview · not the live site · forms do not send

Compliance, Risk & Sustainability

Pass your audit with clean access rights

Fingerprint scanner for secure access

We put SAP access under control: segregation-of-duties rules, role design and clean-up, managed access requests and emergency access, and audit-ready reports and periodic access reviews.

SoD rules

segregation-of-duties checked before access is granted

Clean roles

redesigned so each job gets only what it needs

Audit-ready

reports and periodic access reviews on demand

On premise or cloud

SAP GRC Access Control or SAP Cloud Identity Access Governance

Auditors don’t ask whether people have access. They ask whether anyone could raise a supplier, approve the invoice and pay it, and whether you can prove they couldn’t.

What we put in control

Choose an area to see the problems we solve, what we deliver and the SAP solutions we use.

Access risk and SoD

The problem

  • No clear list of risky access combinations
  • Conflicts found only by auditors
  • Risks accepted without mitigating controls

What we deliver

  • A segregation-of-duties rule set for your processes
  • Risk analysis across users and roles
  • Conflicts removed or mitigated with documented controls
  • Simulation before any access change
  • SAP GRC Access Control
  • SAP Cloud Identity Access Governance

The result: Known access risks, removed or controlled.

Role design and clean-up

The problem

  • Hundreds of roles nobody understands
  • Users with far more access than their job needs
  • Old roles copied for every new hire

What we deliver

  • Job-based role design for S/4HANA and Fiori
  • Clean-up of unused and duplicate roles
  • Role ownership and naming standards
  • Roles built conflict-free from the start
  • SAP role administration
  • Fiori spaces and pages
  • SAP GRC Business Role Management

The result: Simple roles that match real jobs.

Access requests and provisioning

The problem

  • Access requested by email and approved by habit
  • Leavers keeping access for months
  • No record of who approved what

What we deliver

  • Self-service access requests with risk checks
  • Approval workflows with managers and role owners
  • Automatic provisioning and removal
  • Joiner, mover and leaver rules
  • SAP GRC Access Request Management
  • SAP Cloud Identity Services

The result: The right access, granted and removed on time, with a full record.

Emergency access

The problem

  • Shared superuser IDs
  • No log of what was done with emergency access
  • Support teams with permanent high access

What we deliver

  • Firefighter IDs for emergency and support access
  • Reason codes and approvals for every use
  • Logs reviewed by controllers
  • Permanent high access removed
  • SAP GRC Emergency Access Management

The result: Emergency access that is fast, logged and reviewed.

Access reviews and audit

The problem

  • Access reviews done in spreadsheets
  • Evidence gathered in a rush before every audit
  • Repeat audit findings

What we deliver

  • Periodic user access reviews by managers and role owners
  • Audit-ready reports on demand
  • Remediation of past audit findings
  • Continuous monitoring of access risk
  • SAP GRC User Access Review
  • SAP GRC Access Control reports

The result: Audits passed with evidence ready, not rushed.

Process controls and risk

The problem

  • Controls tested by hand once a year
  • Risks tracked in spreadsheets
  • No link between risks, controls and SAP data

What we deliver

  • Automated control monitoring on SAP data
  • Risk register linked to controls
  • Control testing and sign-off workflows
  • Dashboards for risk and compliance teams
  • SAP GRC Process Control
  • SAP GRC Risk Management

The result: Controls monitored continuously, not once a year.

How we deliver

  1. Assess

    Analyse access risk, roles and past audit findings.

    You get: A risk baseline

  2. Design

    SoD rule set, role design and approval model.

    You get: A control design

  3. Implement

    Configure SAP GRC or IAG and clean up roles.

    You get: Working controls

  4. Remediate

    Remove or mitigate conflicts with the business.

    You get: A clean access position

  5. Sustain

    Reviews, monitoring and support with iCare AMS.

    You get: Audit-ready, all year

Before and after

Access today

  • Roles nobody understands
  • Conflicts found by auditors
  • Access requested by email
  • Shared superuser IDs

Access with INK and SAP GRC

  • Simple, job-based roles
  • Risks checked before access is granted
  • Workflow requests with full records
  • Logged, reviewed emergency access

Related: Health Check 360° (GRC & security) · Cybersecurity & Identity · Hire GRC consultants

Get ready for your next audit

Tell us about your last audit findings or your access concerns. We’ll show you the fastest way to a clean access position.

Frequently asked questions

What is segregation of duties?

A control that stops one person from completing a risky process alone, such as creating a supplier, approving its invoice and paying it.

Do we need SAP GRC?

Not always. Smaller landscapes can start with role clean-up and SoD analysis. SAP GRC Access Control or SAP Cloud Identity Access Governance help most when you have many users, systems or audit requirements.

Can you fix our existing audit findings?

Yes. We analyse the findings, remove or mitigate the conflicts with the business, and set up the controls that stop them coming back.

Does this work with S/4HANA and Fiori?

Yes. We design job-based roles for S/4HANA and Fiori, and connect SAP GRC or IAG to both on-premise and cloud systems.

Not sure where to start?

Spend one day with us mapping a single process. You keep the map, whatever you decide next.