Home · Solutions · Legal & compliance

Solution · Legal & compliance

Role conflicts and emergency access reviewed weekly, with the evidence pack already written

Segregation of duties checked weekly, not once a year

Robots pull roles and authorisations out of SAP every week, test them against the rule matrix internal control owns, and put each conflict in front of its owner in Microsoft Teams.

EnterpriseMicrosoft TeamsHuman in the loopDeterministic automation
3,400SAP users across five company codes. Their combined authorisations are examined in full once a year, by the external auditor.

Executive summary

Challenge

The auditor finds your role conflicts once a year. By then the oldest of them is twelve months old.

What changes

Unattended robots sign into each SAP client with a display-only technical account and extract what the rules need: the user master.

Business value

A conflict is visible in the week it is created, not in an audit letter eleven months later, and the assignment behind it is named.

Systems involved

SharePoint evidence library; Microsoft Lists register; Power BI semantic model

Business problem

Internal control

A listed group has to answer one question about its ERP: who could, acting alone, create a supplier, change its bank account and release the payment. Not who did. Who could. That answer is stored nowhere. It is assembled from role assignments, composite role resolutions and authorisation values, and it changes whenever somebody is promoted, covers a colleague or joins a project.

Assembling it is expensive, so it happens rarely. The matrix is a workbook a controller built three years ago and nobody has owned since; the extract is a report an administrator runs when asked; the analysis is lookup formulas across five files. Two people spend a day on it, so it happens when the auditor is coming. Nor does anyone own the whole thing: internal control owns the answer but not the data, the authorisations team owns the data but not the rules, and process owners carry the risk but read it once a year as role names.

Privileged access is the sharper edge. When posting fails on the last day of the close, somebody is given wide authorisations for a few hours. That grant is an email, and the review of what the person then did is a log opened only if an auditor names a session.

How it works today

Five workbooks and a rule file nobody has reviewed for two years: that is how segregation of duties is checked in groups without a dedicated access-risk product.

  1. PersonInternal control asks the authorisations team for an extract of users, roles and profiles, usually because an audit deadline is near
  2. SystemThe administrator runs the standard user information reports for each of the five company codes and emails five workbooks
  3. WaitingThey sit until somebody has a clear day, because composite and derived roles must be resolved first
  4. PersonConflicts are found with lookup formulas against a rule workbook last reviewed two years ago, whose author has left
  5. Risk of errorThe extract is stale by the day it is analysed, and nobody can prove it covered every user in every client
  6. PersonThe list goes to process owners as an email attachment; answers return as comments in different copies
  7. WaitingEmergency grants are recorded in a ticket, and the log behind them is read only if the auditor names a session
PersonSystemWaitingRisk of error

Why the current process costs more than it appears

Time that disappears before anyone measures it.

  • Two people for a day is the visible number. The week after it is not: chasing owners, resolving roles by hand, rebuilding a workbook nobody documented.
  • An annual snapshot cannot say how long a conflict existed. One found in March may date from the previous April, with eleven months of postings behind it.
  • A row holding a user ID, a role name and a risk letter tells a plant manager nothing about what that person can do, so it is acknowledged rather than fixed.
  • Accepted risks decay quietly. A conflict accepted in 2023 is still accepted, though its mitigating control was a report run by a controller who has left.
  • Privileged access leaves the thinnest evidence of all: the grant is documented, the session is not, and reconstructing it a year later costs far more than reviewing it would have.

Cost of inaction

Twelve months of this review done by hand≈ €30,720
The clean-up after one annual audit list, 30 person-days≈ €9,600
Both, from this audit cycle to the one after next≈ €120,960

Twice a year is what the company affords, not what the control needs. The list simply arrives from outside the company, dated and addressed to the audit committee, and the next quarter goes on explaining conflicts that could have been closed in a week. Thirty person-days a year of clean-up is conservative for five company codes.

The exposure in neither row is time. A conflict that stood for eleven months is eleven months of postings somebody would have to reconstruct, and an accepted risk whose control quietly stopped being performed is a control the group reports as effective and does not have.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

A listed manufacturing group in Central Europe: five SAP company codes on one S/4HANA system, about 3,400 named SAP users, Microsoft 365 E3 with Power BI, three people in internal control, and no SAP Access Control licence.

Volume

Around 9,000 role assignments, 40 to 60 assignment changes a week, 60 to 90 emergency access grants a year, and a matrix of about 120 conflict pairs.

Current process

Extracts on request, analysed in Excel, once before the statutory audit and once at half-year. Emergency grants approved in a ticket, with the security audit log read only when somebody names a session.

Bottleneck

Running this review weekly, as the control needs, would take two people a full day each week. That is why it runs twice a year, and why the conflict list arrives from the auditor.

Solution

Robots extract users, assignments, role resolutions and the authorisation values behind each rule from every company code weekly, apply the matrix internal control maintains, and attribute each new conflict to the assignment that created it. Each open conflict becomes a task for its owner in Microsoft Teams: remediate, accept with a mitigating control, or dispute the rule. Emergency sessions are reconciled against the log and sampled.

Potential outcome

The detection gap falls from months to a week, internal control produces the annual conflict list before the auditor does, and the evidence pack builds continuously. Illustrative figures, not a client result.

Proposed solution

Unattended robots sign into each SAP client with a display-only technical account and extract what the rules need: the user master, role and profile assignments, composite and derived role resolutions, and the authorisation values that decide whether a transaction is usable at all. The extract lands in a dated SharePoint folder with a control total, so completeness is demonstrated rather than assumed.

The matrix stays with internal control, in a form they can change without asking anyone: an Excel workbook on SharePoint, or Microsoft Lists where versioned rows suit the team better. Each rule names two functions, the transactions and authorisation objects behind each, a risk rating, the company codes it covers and an owner. The robot reads the version in force that week and stamps it onto the result, so any conflict list can be explained by the rules that existed on the day.

Conflicts then become work rather than a report. This week's set is compared with last week's, separating new from carried over and cleared, and each new conflict is traced to the assignment that introduced it. It reaches its owner in Microsoft Teams with the user, the company code and both functions described in business language. The owner remediates, accepts with a named control, or disputes the rule; acceptances need a justification and expire. Emergency grants are reconciled against what the account actually did, and sampling rules decide which sessions a person reads.

One thing should be said plainly. SAP sells software for exactly this: SAP Access Control, part of its governance, risk and compliance portfolio, and SAP Cloud Identity Access Governance for cloud landscapes. Both do risk analysis, mitigating controls and emergency access management, with a rule set SAP maintains. If your group has it licensed and covering the landscape, use it. This is for the groups that do not, and as a complement where it does not reach: the warehouse application, treasury, payroll, the plant systems.

Native capabilities used

UiPath Orchestrator time triggers, queues and audit log; UiPath SAP automation activities and the SAP BAPI and OData connectors in UiPath Integration Service; UiPath Action Center tasks as actionable notifications in Microsoft Teams; Microsoft Lists and Excel on SharePoint with version history; Microsoft Teams Approvals app; Power BI

What we build

Extraction robots per SAP client, role resolution, the rule engine, the week-on-week comparison and cause attribution, the register with expiry logic, owner tasks with escalation, sampling rules, the evidence pack and the dashboard

Custom integration

SAP read access through UiPath SAP activities and OData services where exposed; security audit log and change document extraction per client; reconciliation of SAP accounts against leavers in Microsoft Entra ID

How the automated process works

  1. AutomationA weekend time trigger extracts users, assignments, role resolutions and the relevant authorisation values per client, with a control total
  2. AutomationThe robot reads the matrix version in force and applies each rule at user and company code level
  3. SystemThis week's conflicts are compared with last week's, and every new one is traced to the assignment change behind it
  4. AutomationConflicts covered by a valid register entry are marked mitigated; entries past their expiry date reopen
  5. PersonThe owner answers in Microsoft Teams: remediate, accept with a mitigating control, or dispute the rule, with a justification mandatory for acceptance
  6. AutomationEmergency grants are reconciled against the security audit log and the documents changed in each session; sampling rules select what must be reviewed
  7. PersonA reviewer reads the selected sessions in Teams with the transaction list, changed documents and original justification attached
  8. AutomationExtract, rule version, conflicts, decisions and sampled sessions are filed as that week's evidence pack, and the Power BI dashboard refreshes
AutomationSystemPerson

Human-in-the-loop model

Automation handles

  • Extraction from every SAP client on schedule, including role resolution and authorisation values
  • The rule version in force, and the comparison separating new conflicts from carried-over ones
  • Matching conflicts to valid controls, reopening expired ones, chasing owners who have not answered
  • The evidence pack and the reconciliation showing every user in every client was covered

People decide

  • Whether a conflict is remediated or accepted with a named control, and who signs that
  • What the matrix contains: which function pairs conflict, at what rating, in which company codes
  • Which emergency sessions must always be sampled, and what an acceptable justification looks like
  • Whether a disputed rule is wrong, in which case internal control versions the change

Before and after

BeforeAfter
Frequency of a full conflict reviewonce or twice a yearevery week
Time between a conflict arising and being seenup to eleven monthsup to seven days
Cause of a new conflictreconstructed by hand, if at allnamed with the assignment behind it
Emergency sessions reviewedwhen the auditor askssampled monthly, high-risk ones always
Evidence for the auditorrebuilt from mailboxes and workbooksfiled weekly with the rule version used

Systems and integrations

Where a rule suffices we do not use a model. Where judgement is needed, a person decides.

Inputs

  • SAP user master and role assignments per company code
  • composite and derived role resolutions with authorisation values
  • SAP security audit log and change documents
  • the rule matrix and the register

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath SAP automation activities
  • UiPath Integration Service
  • UiPath Action Center

Target systems

  • SharePoint evidence library
  • Microsoft Lists register
  • Power BI semantic model

Human touchpoints: Action Center tasks in Microsoft Teams; Microsoft Teams Approvals for risk acceptance; the weekly summary in the internal control channel

SAP user masterUiPath OrchestratorUiPath RobotsSharePoint evidence libraryAction Center tasks in Microsoft Teams

Technologies used

UiPath Robots and UiPath Orchestrator

weekly extraction per SAP client on a time trigger, queues, retries and audit trail

A
UiPath SAP automation (SAP BAPI and OData connectors, SAP GUI activities)

reads users, assignments, role resolutions and authorisation values

A
UiPath Action Center in Microsoft Teams

conflict decisions and session reviews completed as tasks inside Teams

A
UiPath Integration Service (Microsoft OneDrive & SharePoint and Microsoft Teams connectors)

reads the matrix, files the evidence pack, posts the weekly summary

A
Microsoft Lists and Microsoft Excel on SharePoint

the rule matrix and the register, owned by internal control with version history

A
Microsoft Teams Approvals app

sign-off on risk acceptances by the executive who carries the risk

A
Power BI

trend dashboard: conflicts by company code, ageing, emergency sessions by month

A
Microsoft Entra ID

reconciliation of SAP accounts against joiners and leavers

A
Averified product capability (vendor documentation)

Illustrative economic model

Start by questioning the assumptions.

Illustrative model
8 person-days of review a month × 480 minutes= 64 h / month
64 h × €40 fully loaded hourly cost= €2,560 / month
× 12 months≈ €30,720 / year
Annual cost of running this control by hand (illustrative)≈ €30,720

Nobody timed this at a client; the ranges are typical for the scenario above. They price the manual equivalent of the control at the frequency it needs, not a cost already in a budget line: reviewing by hand every week takes two people a full day each, which is why most groups review twice a year. The rate of €40 an hour is a fully loaded cost for internal control and authorisations staff in Central Europe.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • A conflict is visible in the week it is created, not in an audit letter eleven months later, and the assignment behind it is named
  • The annual list stops being a surprise: internal control holds it before the auditor produces it, already triaged
  • Accepted risks carry an owner, a justification and an expiry date, so the register describes the company as it is
  • Privileged access stops being a grant with no follow-up; what the account did is reconciled and sampled every month
  • Audit preparation becomes a review of evidence that already exists, because the pack is assembled every week

The management view

  • The audit committee can be told how many conflicts exist, how old they are and who owns each, without ordering an extract
  • Risk acceptance becomes a decision with a name, a justification and a date, which is what an internal control statement should rest on
  • The control costs about the same at three company codes or fifteen, because the effort sits in the rules
  • Segregation of duties stops depending on one person's workbook and becomes a process that survives their departure

Board-level KPIs

open high-risk conflictsaverage age of an open conflictnew conflicts per monthshare of emergency sessions reviewed within the sampling ruleoverdue risk acceptances

Security and governance

An auditor should be able to reconstruct every decision.

  • The extraction account is display-only in every client. A control that reads authorisations must never be able to grant them
  • Nobody may author a rule, own the resulting conflict and approve its acceptance; the flow enforces that separation and records who did what
  • SAP credentials are drawn from your existing vault rather than the flow; the extracts, decisions and evidence the control produces are held in your Microsoft 365 tenant and the EU region of UiPath Automation Cloud
  • Role data is personal data: the evidence library carries a Microsoft Purview retention label, and every change to the matrix is versioned with an author and a date

Why now

01

The next audit letter will be written from one extract taken in one week of the year, by somebody outside the company. Producing the same analysis weekly costs a modelled €2,560 a month and moves that list to your side of the table

02

Role landscapes are moving. S/4HANA programmes, new company codes and shared-service consolidations redistribute authorisations, and each creates conflicts nobody watches for

03

The extraction that used to need a consultant is now a scheduled robot on standard interfaces, and the review that needed a portal fits into Microsoft Teams

Relevant executive roles

CFO

The internal control statement rests on conflicts and acceptances that are current, named and dated rather than on a workbook from last spring

Head of Internal Control

The matrix and the register stay under their ownership, and the analysis they cannot afford to run weekly runs weekly

CIO

Authorisation risk becomes a measured number instead of an annual argument about whether the extract was complete

Head of Internal Audit

Testing shifts from proving the control exists to sampling its output

Common questions and objections

We already have SAP Access Control, so why would we need this?

Then use it. It does risk analysis, mitigating controls and emergency access management properly, and SAP maintains the rule set. This pattern is for groups without that licence, and as a complement where it does not reach: the warehouse system, treasury, payroll and plant applications.

Our rule matrix is out of date and we do not trust it.

That is the normal starting point and the part we do first. We rebuild the rules behind the conflicts your last two audit letters reported, then add the rest in waves. Forty rules owners trust beat four hundred nobody reads.

Won't a weekly report overwhelm the process owners?

The weekly run reports what changed, not the whole population. After the first clean-up most weeks bring a handful of new conflicts, each attributed to an assignment, and each owner sees only their own queue.

When this is not the right solution

  • A small, simply built user base: under a few hundred ERP users with a straightforward role design, an annual review by one person is proportionate to the risk
  • SAP Access Control or SAP Cloud Identity Access Governance already licensed and covering the whole landscape; extend that rather than build alongside it
  • Role design so unstable that most users carry a role built for them individually, in which case the list describes the role catalogue rather than the risk

A question for the next management meeting

When did we last know, with evidence, how many people in this group could act alone to create a supplier, change its bank account and release the payment?

Implementation approach

We start with one slice of the process and extend only once it is proven.

We deliver

  • A working session that turns internal control's rule workbook into a maintainable matrix: functions, transactions, authorisation objects, ratings, owners
  • Extraction robots for each SAP client, with role resolution and a completeness control total per run
  • The rule engine, the week-on-week comparison and the attribution of every new conflict
  • The register of mitigating controls with owners, evidence and expiry dates, and the logic that reopens a conflict when a control lapses
  • Conflict tasks, risk acceptance and escalation in Microsoft Teams, the sampling rules, the evidence pack and the Power BI dashboard

We need from you

  • Your current rule set in whatever form it exists, and the conflicts your last two audit letters reported
  • A display-only technical account in each SAP client, with the security audit log configured for the accounts that matter
  • Named owners for roles and processes, and confirmation that whoever changes the matrix is not whoever approves acceptances

Stages

Discovery

Rule set, landscape, company codes, owners and the conflicts your auditor already reported

Design

Matrix structure, extraction scope, sampling rules, task routing, evidence pack layout

Build

Extraction robots, rule engine, register, Teams tasks and the dashboard

Validation

Parallel run against a manual review of two company codes, counts reconciled line by line

Go-live

First live weekly cycle under internal control supervision, then the remaining company codes

Enterprise. Effort is driven by the number of SAP clients and company codes, the state of the role design, the size of the matrix, and what the security audit log records.