Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

SAP SoD and manufacturing compliance: where the audit scope actually lands


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20538
Topic starter  

TL;DR: SAP segregation of duties helps manufacturing teams catch conflicting actions inside SAP, but OpenIAM argues that auditors test access control, identity lifecycle, and certification across SAP plus connected systems. The real gap is evidence: a conflict finding is only useful when reviewer decisions, remediation, and timestamps are all retrievable.

NHIMG editorial — based on content published by OpenIAM: Why SAP SoD Is Not Enough for Manufacturing Compliance

By the numbers:

Questions worth separating out

Q: What breaks when SAP SoD is only enforced inside one application?

A: Cross-system conflicts remain invisible.

Q: Why do auditors care about evidence after an SoD conflict is found?

A: Because detection alone does not prove governance.

Q: How should manufacturing teams govern access reviews across SAP and connected systems?

A: Use one certification model for the business process, not separate reviews for each application.

Practitioner guidance

  • Expand SoD scope beyond SAP-native rules Map financially material workflows end to end, including SAP, Active Directory, Entra ID, HR, contractor platforms, and any approval system that participates in the transaction chain.
  • Bind lifecycle events to every in-scope system Ensure joiner, mover, and leaver changes revoke or adjust access across all systems that can create or complete a conflicted transaction, not only the SAP role assignment.
  • Capture evidence as part of the workflow Record who reviewed the conflict, what they decided, what compensating control was accepted, and when remediation occurred in a single retrievable record.

What's in the full article

OpenIAM's full article covers the operational detail this post intentionally leaves for the source:

  • The SAP-specific SoD conflict examples used in manufacturing audits and how they map to common financial control objectives.
  • The five-step evidence chain auditors expect after a conflict is detected, including review, decision, remediation, and timestamps.
  • The seven-step manufacturing governance model that extends beyond SAP into HR, directory, contractor, and service-account controls.
  • The platform treatment of how SoD findings are documented and tracked across connected systems.

👉 Read OpenIAM's analysis of why SAP SoD is not enough for manufacturing compliance →

SAP SoD and manufacturing compliance: where the audit scope actually lands?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20129
 

Manufacturing compliance is an identity governance problem, not a single-application control problem. SAP SoD is necessary, but auditors test the broader path by which access is granted, changed, and evidenced across SAP, directory services, HR systems, and approval workflows. A programme that stops at the SAP boundary can look controlled while still failing the actual audit question, which is whether the organisation can prove who had access, who reviewed it, and what changed after the finding.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.

A question worth separating out:

Q: What is the difference between SAP SoD detection and enterprise identity governance?

A: SAP SoD detection finds conflicting role combinations inside SAP. Enterprise identity governance connects SAP with directory, HR, contractor, and workflow systems so lifecycle changes, approvals, and evidence are governed across the full environment where the transaction actually happens.

👉 Read our full editorial: SAP SoD is not enough for manufacturing compliance



   
ReplyQuote
Share: