Home · Solutions · Legal & compliance
Solution · Legal & complianceRole conflicts and emergency access reviewed weekly, with the evidence pack already written
Segregation of duties checked weekly, not once a year
Robots pull roles and authorisations out of SAP every week, test them against the rule matrix internal control owns, and put each conflict in front of its owner in Microsoft Teams.
Executive summary
The auditor finds your role conflicts once a year. By then the oldest of them is twelve months old.
Unattended robots sign into each SAP client with a display-only technical account and extract what the rules need: the user master.
A conflict is visible in the week it is created, not in an audit letter eleven months later, and the assignment behind it is named.
SharePoint evidence library; Microsoft Lists register; Power BI semantic model
Business problem
Internal control
A listed group has to answer one question about its ERP: who could, acting alone, create a supplier, change its bank account and release the payment. Not who did. Who could. That answer is stored nowhere. It is assembled from role assignments, composite role resolutions and authorisation values, and it changes whenever somebody is promoted, covers a colleague or joins a project.
Assembling it is expensive, so it happens rarely. The matrix is a workbook a controller built three years ago and nobody has owned since; the extract is a report an administrator runs when asked; the analysis is lookup formulas across five files. Two people spend a day on it, so it happens when the auditor is coming. Nor does anyone own the whole thing: internal control owns the answer but not the data, the authorisations team owns the data but not the rules, and process owners carry the risk but read it once a year as role names.
Privileged access is the sharper edge. When posting fails on the last day of the close, somebody is given wide authorisations for a few hours. That grant is an email, and the review of what the person then did is a log opened only if an auditor names a session.
How it works today
Five workbooks and a rule file nobody has reviewed for two years: that is how segregation of duties is checked in groups without a dedicated access-risk product.
- PersonInternal control asks the authorisations team for an extract of users, roles and profiles, usually because an audit deadline is near
- SystemThe administrator runs the standard user information reports for each of the five company codes and emails five workbooks
- WaitingThey sit until somebody has a clear day, because composite and derived roles must be resolved first
- PersonConflicts are found with lookup formulas against a rule workbook last reviewed two years ago, whose author has left
- Risk of errorThe extract is stale by the day it is analysed, and nobody can prove it covered every user in every client
- PersonThe list goes to process owners as an email attachment; answers return as comments in different copies
- WaitingEmergency grants are recorded in a ticket, and the log behind them is read only if the auditor names a session
Why the current process costs more than it appears
Time that disappears before anyone measures it.
- Two people for a day is the visible number. The week after it is not: chasing owners, resolving roles by hand, rebuilding a workbook nobody documented.
- An annual snapshot cannot say how long a conflict existed. One found in March may date from the previous April, with eleven months of postings behind it.
- A row holding a user ID, a role name and a risk letter tells a plant manager nothing about what that person can do, so it is acknowledged rather than fixed.
- Accepted risks decay quietly. A conflict accepted in 2023 is still accepted, though its mitigating control was a report run by a controller who has left.
- Privileged access leaves the thinnest evidence of all: the grant is documented, the session is not, and reconstructing it a year later costs far more than reviewing it would have.
Cost of inaction
Twice a year is what the company affords, not what the control needs. The list simply arrives from outside the company, dated and addressed to the audit committee, and the next quarter goes on explaining conflicts that could have been closed in a week. Thirty person-days a year of clean-up is conservative for five company codes.
The exposure in neither row is time. A conflict that stood for eleven months is eleven months of postings somebody would have to reconstruct, and an accepted risk whose control quietly stopped being performed is a control the group reports as effective and does not have.
A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.
A listed manufacturing group in Central Europe: five SAP company codes on one S/4HANA system, about 3,400 named SAP users, Microsoft 365 E3 with Power BI, three people in internal control, and no SAP Access Control licence.
Around 9,000 role assignments, 40 to 60 assignment changes a week, 60 to 90 emergency access grants a year, and a matrix of about 120 conflict pairs.
Extracts on request, analysed in Excel, once before the statutory audit and once at half-year. Emergency grants approved in a ticket, with the security audit log read only when somebody names a session.
Running this review weekly, as the control needs, would take two people a full day each week. That is why it runs twice a year, and why the conflict list arrives from the auditor.
Robots extract users, assignments, role resolutions and the authorisation values behind each rule from every company code weekly, apply the matrix internal control maintains, and attribute each new conflict to the assignment that created it. Each open conflict becomes a task for its owner in Microsoft Teams: remediate, accept with a mitigating control, or dispute the rule. Emergency sessions are reconciled against the log and sampled.
The detection gap falls from months to a week, internal control produces the annual conflict list before the auditor does, and the evidence pack builds continuously. Illustrative figures, not a client result.
Proposed solution
Unattended robots sign into each SAP client with a display-only technical account and extract what the rules need: the user master, role and profile assignments, composite and derived role resolutions, and the authorisation values that decide whether a transaction is usable at all. The extract lands in a dated SharePoint folder with a control total, so completeness is demonstrated rather than assumed.
The matrix stays with internal control, in a form they can change without asking anyone: an Excel workbook on SharePoint, or Microsoft Lists where versioned rows suit the team better. Each rule names two functions, the transactions and authorisation objects behind each, a risk rating, the company codes it covers and an owner. The robot reads the version in force that week and stamps it onto the result, so any conflict list can be explained by the rules that existed on the day.
Conflicts then become work rather than a report. This week's set is compared with last week's, separating new from carried over and cleared, and each new conflict is traced to the assignment that introduced it. It reaches its owner in Microsoft Teams with the user, the company code and both functions described in business language. The owner remediates, accepts with a named control, or disputes the rule; acceptances need a justification and expire. Emergency grants are reconciled against what the account actually did, and sampling rules decide which sessions a person reads.
One thing should be said plainly. SAP sells software for exactly this: SAP Access Control, part of its governance, risk and compliance portfolio, and SAP Cloud Identity Access Governance for cloud landscapes. Both do risk analysis, mitigating controls and emergency access management, with a rule set SAP maintains. If your group has it licensed and covering the landscape, use it. This is for the groups that do not, and as a complement where it does not reach: the warehouse application, treasury, payroll, the plant systems.
UiPath Orchestrator time triggers, queues and audit log; UiPath SAP automation activities and the SAP BAPI and OData connectors in UiPath Integration Service; UiPath Action Center tasks as actionable notifications in Microsoft Teams; Microsoft Lists and Excel on SharePoint with version history; Microsoft Teams Approvals app; Power BI
Extraction robots per SAP client, role resolution, the rule engine, the week-on-week comparison and cause attribution, the register with expiry logic, owner tasks with escalation, sampling rules, the evidence pack and the dashboard
SAP read access through UiPath SAP activities and OData services where exposed; security audit log and change document extraction per client; reconciliation of SAP accounts against leavers in Microsoft Entra ID
How the automated process works
- AutomationA weekend time trigger extracts users, assignments, role resolutions and the relevant authorisation values per client, with a control total
- AutomationThe robot reads the matrix version in force and applies each rule at user and company code level
- SystemThis week's conflicts are compared with last week's, and every new one is traced to the assignment change behind it
- AutomationConflicts covered by a valid register entry are marked mitigated; entries past their expiry date reopen
- PersonThe owner answers in Microsoft Teams: remediate, accept with a mitigating control, or dispute the rule, with a justification mandatory for acceptance
- AutomationEmergency grants are reconciled against the security audit log and the documents changed in each session; sampling rules select what must be reviewed
- PersonA reviewer reads the selected sessions in Teams with the transaction list, changed documents and original justification attached
- AutomationExtract, rule version, conflicts, decisions and sampled sessions are filed as that week's evidence pack, and the Power BI dashboard refreshes
Human-in-the-loop model
Automation handles
- Extraction from every SAP client on schedule, including role resolution and authorisation values
- The rule version in force, and the comparison separating new conflicts from carried-over ones
- Matching conflicts to valid controls, reopening expired ones, chasing owners who have not answered
- The evidence pack and the reconciliation showing every user in every client was covered
People decide
- Whether a conflict is remediated or accepted with a named control, and who signs that
- What the matrix contains: which function pairs conflict, at what rating, in which company codes
- Which emergency sessions must always be sampled, and what an acceptable justification looks like
- Whether a disputed rule is wrong, in which case internal control versions the change
Before and after
Systems and integrations
Where a rule suffices we do not use a model. Where judgement is needed, a person decides.
Inputs
- SAP user master and role assignments per company code
- composite and derived role resolutions with authorisation values
- SAP security audit log and change documents
- the rule matrix and the register
Automation layer
- UiPath Orchestrator
- UiPath Robots
- UiPath SAP automation activities
- UiPath Integration Service
- UiPath Action Center
Target systems
- SharePoint evidence library
- Microsoft Lists register
- Power BI semantic model
Human touchpoints: Action Center tasks in Microsoft Teams; Microsoft Teams Approvals for risk acceptance; the weekly summary in the internal control channel
Technologies used
weekly extraction per SAP client on a time trigger, queues, retries and audit trail
Areads users, assignments, role resolutions and authorisation values
Aconflict decisions and session reviews completed as tasks inside Teams
Areads the matrix, files the evidence pack, posts the weekly summary
Athe rule matrix and the register, owned by internal control with version history
Asign-off on risk acceptances by the executive who carries the risk
Atrend dashboard: conflicts by company code, ageing, emergency sessions by month
Areconciliation of SAP accounts against joiners and leavers
AIllustrative economic model
Start by questioning the assumptions.
Nobody timed this at a client; the ranges are typical for the scenario above. They price the manual equivalent of the control at the frequency it needs, not a cost already in a budget line: reviewing by hand every week takes two people a full day each, which is why most groups review twice a year. The rate of €40 an hour is a fully loaded cost for internal control and authorisations staff in Central Europe.
Run the numbers on your data
An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.
Business benefits
- A conflict is visible in the week it is created, not in an audit letter eleven months later, and the assignment behind it is named
- The annual list stops being a surprise: internal control holds it before the auditor produces it, already triaged
- Accepted risks carry an owner, a justification and an expiry date, so the register describes the company as it is
- Privileged access stops being a grant with no follow-up; what the account did is reconciled and sampled every month
- Audit preparation becomes a review of evidence that already exists, because the pack is assembled every week
The management view
- The audit committee can be told how many conflicts exist, how old they are and who owns each, without ordering an extract
- Risk acceptance becomes a decision with a name, a justification and a date, which is what an internal control statement should rest on
- The control costs about the same at three company codes or fifteen, because the effort sits in the rules
- Segregation of duties stops depending on one person's workbook and becomes a process that survives their departure
Board-level KPIs
Security and governance
An auditor should be able to reconstruct every decision.
- The extraction account is display-only in every client. A control that reads authorisations must never be able to grant them
- Nobody may author a rule, own the resulting conflict and approve its acceptance; the flow enforces that separation and records who did what
- SAP credentials are drawn from your existing vault rather than the flow; the extracts, decisions and evidence the control produces are held in your Microsoft 365 tenant and the EU region of UiPath Automation Cloud
- Role data is personal data: the evidence library carries a Microsoft Purview retention label, and every change to the matrix is versioned with an author and a date
Why now
The next audit letter will be written from one extract taken in one week of the year, by somebody outside the company. Producing the same analysis weekly costs a modelled €2,560 a month and moves that list to your side of the table
Role landscapes are moving. S/4HANA programmes, new company codes and shared-service consolidations redistribute authorisations, and each creates conflicts nobody watches for
The extraction that used to need a consultant is now a scheduled robot on standard interfaces, and the review that needed a portal fits into Microsoft Teams
Relevant executive roles
The internal control statement rests on conflicts and acceptances that are current, named and dated rather than on a workbook from last spring
The matrix and the register stay under their ownership, and the analysis they cannot afford to run weekly runs weekly
Authorisation risk becomes a measured number instead of an annual argument about whether the extract was complete
Testing shifts from proving the control exists to sampling its output
Common questions and objections
Then use it. It does risk analysis, mitigating controls and emergency access management properly, and SAP maintains the rule set. This pattern is for groups without that licence, and as a complement where it does not reach: the warehouse system, treasury, payroll and plant applications.
That is the normal starting point and the part we do first. We rebuild the rules behind the conflicts your last two audit letters reported, then add the rest in waves. Forty rules owners trust beat four hundred nobody reads.
The weekly run reports what changed, not the whole population. After the first clean-up most weeks bring a handful of new conflicts, each attributed to an assignment, and each owner sees only their own queue.
When this is not the right solution
- A small, simply built user base: under a few hundred ERP users with a straightforward role design, an annual review by one person is proportionate to the risk
- SAP Access Control or SAP Cloud Identity Access Governance already licensed and covering the whole landscape; extend that rather than build alongside it
- Role design so unstable that most users carry a role built for them individually, in which case the list describes the role catalogue rather than the risk
A question for the next management meeting
When did we last know, with evidence, how many people in this group could act alone to create a supplier, change its bank account and release the payment?
Implementation approach
We start with one slice of the process and extend only once it is proven.
We deliver
- A working session that turns internal control's rule workbook into a maintainable matrix: functions, transactions, authorisation objects, ratings, owners
- Extraction robots for each SAP client, with role resolution and a completeness control total per run
- The rule engine, the week-on-week comparison and the attribution of every new conflict
- The register of mitigating controls with owners, evidence and expiry dates, and the logic that reopens a conflict when a control lapses
- Conflict tasks, risk acceptance and escalation in Microsoft Teams, the sampling rules, the evidence pack and the Power BI dashboard
We need from you
- Your current rule set in whatever form it exists, and the conflicts your last two audit letters reported
- A display-only technical account in each SAP client, with the security audit log configured for the accounts that matter
- Named owners for roles and processes, and confirmation that whoever changes the matrix is not whoever approves acceptances
Stages
Discovery
Rule set, landscape, company codes, owners and the conflicts your auditor already reported
Design
Matrix structure, extraction scope, sampling rules, task routing, evidence pack layout
Build
Extraction robots, rule engine, register, Teams tasks and the dashboard
Validation
Parallel run against a manual review of two company codes, counts reconciled line by line
Go-live
First live weekly cycle under internal control supervision, then the remaining company codes
Enterprise. Effort is driven by the number of SAP clients and company codes, the state of the role design, the size of the matrix, and what the security audit log records.
The external auditor finds your segregation conflicts before internal control does.
Send us your rule matrix, however rough, and a user and role extract from one company code. We come back with the conflicts it contains today and a view of which your auditor is likely to raise.
Run your rules against one company codeThe neighbouring process usually has the same problem
Managers sign off on entitlements they cannot read, and nobody withdraws what nobody uses.
View solution Legal & complianceCounterparty screening: sanctions, VAT status, registersYour counterparty file was true on the day you checked it. Sanctions and VAT status moved after that.
View solution IT & servicesData migration validated by testing, not spot checksA spreadsheet sample of a few hundred records is what currently stands between your migration and go-live.
View solutionIndustries we deliver this in most oftenManufacturing & industryRetail & e‑commerceShared services