Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should enterprises automate segregation of duties reviews…
Governance, Ownership & Risk

How should enterprises automate segregation of duties reviews across SAP and connected business applications?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

Enterprises should move from role only reviews to activity based controls that correlate what users actually do with what they are allowed to do. The goal is to surface real risk across SAP and connected systems, automate evidence collection, and produce audit ready reviews without relying on spreadsheets or periodic manual sampling.

Why This Matters for Security Teams

segregation of duties reviews fail when they are treated as a quarterly checkbox instead of a continuous control problem. In SAP estates, risk rarely sits in a single role. It emerges when a user, service account, integration user, or privileged workflow can combine actions across ERP, procurement, finance, and adjacent applications. That is why activity-based review is more effective than role-only attestation, especially where NIST SP 800-53 Rev 5 Security and Privacy Controls emphasizes accountable control operation and evidence. NHIMG’s Ultimate Guide to NHIs — Why NHI Security Matters Now underscores why this matters: only 5.7% of organisations have full visibility into their service accounts, and 97% of NHIs carry excessive privileges. The practical risk is that connected business applications extend SAP access paths beyond the original role catalog. A reviewer can approve a clean-looking role while missing toxic combinations that appear only when transaction logs, workflow traces, API calls, and delegated access are correlated. In practice, many security teams discover SoD exposure only after audit exceptions, fraud reviews, or a production incident have already exposed the gap.

How It Works in Practice

Effective automation starts by joining identity, entitlement, and activity data into a single review pipeline. SAP roles and authorizations should be mapped to business functions, then correlated with actual execution evidence from SAP audit logs, middleware, GRC tools, workflow platforms, and connected applications. The goal is to identify what a person or service can do, what they actually did, and whether any combination creates an SoD conflict that matters to the business. A workable operating model usually includes:
  • Role and entitlement inventory across SAP and downstream systems, refreshed continuously.
  • Activity ingestion from SAP transactions, approval events, API calls, and privileged sessions.
  • Policy rules that flag toxic combinations, compensating controls, and exceptions with expiration dates.
  • Reviewer workflows that route only material exceptions, not every entitlement line item.
  • Evidence capture that preserves who approved, what was reviewed, and what logs supported the decision.
This aligns with control expectations in NIST SP 800-53 Rev 5, which expects access enforcement and auditability to be operational, not theoretical. It also reflects the lessons in NHIMG’s SAP Breach research, where SAP exposure is rarely isolated to one system and often involves adjacent identities and weak cross-system governance. Current guidance suggests that the most reliable reviews are event driven, with periodic certification used as a backstop rather than the primary control. These controls tend to break down when SAP is tightly coupled to custom code and legacy middleware because the business meaning of a transaction is lost outside the source application.

Common Variations and Edge Cases

Tighter SoD automation often increases data integration and governance overhead, so organisations have to balance review precision against system complexity and reviewer fatigue. That tradeoff is especially sharp in mixed SAP environments, where cloud applications, custom ABAP logic, robotic process automation, and shared service accounts all create different evidence formats. Best practice is evolving in three areas. First, some teams review only human users at first, then extend the same logic to service and integration accounts once they can reliably trace machine activity. Second, compensating controls are sometimes accepted for unavoidable conflicts, but only when they are time bound, logged, and independently validated. Third, there is no universal standard for how much telemetry is enough for an audit-ready SoD review, so policy teams should define minimum evidence thresholds rather than rely on vendor defaults. NHIMG’s SAP SQL Anywhere Monitor Hardcoded Credentials case shows why connected applications matter: SoD risk can be undermined by credentials and access paths that bypass the review process entirely. The most effective programs therefore treat entitlement review, credential governance, and activity monitoring as one control chain, not separate projects. Enterprises that split these functions often end up with clean certifications and unresolved operational risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03SoD reviews fail when long-lived credentials and overprivilege are not governed.
OWASP Agentic AI Top 10Automated reviews depend on trustworthy machine actions and constrained execution paths.
CSA MAESTROConnected business apps need runtime policy checks across tool use and delegated actions.
NIST CSF 2.0PR.AC-4Least-privilege and access review controls underpin SoD governance across systems.
NIST AI RMFAutomated SoD reviews need governance, traceability, and risk-based oversight.

Treat autonomous workflows as high-risk actors and constrain their approvals, tools, and escalation paths.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org