Migrating to SAP S/4HANA via RISE is a major step forward. But does your access control keep pace? In this blog we explain what access risks come with RISE migrations - and how to ensure your roles and controls are as clean as your new environment.
RISE with SAP is SAP's Business Transformation as a Service offering: a structured path to migrate your on-premise SAP ERP to SAP S/4HANA Cloud. It promises cleaner processes, lower infrastructure costs, and a future-proof platform.
What it does not promise is clean access control. Cloud migration does not transfer accountability for SAP security outcomes to SAP. If required customer-side controls are not implemented and maintained, the organisation bears the risk.
That is the part many organisations discover too late.
Migration projects move fast. Deadlines are tight, workstreams run in parallel, and access design is rarely the top priority. The result is predictable: during migrations, roles are upgraded to meet deadlines. New access combinations are introduced but not understood. Risk laden combinations survive go-live.
Common access risks that emerge during and after RISE migration:
Many organisations still approach the transition as a lift-and-shift exercise. Access models are carried forward with the expectation they can be addressed later. Under cloud operating models, that delay becomes a liability.
A 2025 SAPinsider Research Report revealed that 23% of organisations reported experiencing a cybersecurity attack that impacted their SAP environment in the past year. Migrations are a peak vulnerability window - systems are in flux, governance models are under pressure, and nobody has a complete picture of who has access to what.
Excessive user access increases the risk of fraud, operational inefficiency, and compliance exposure — all at a moment when your organisation is already stretched by the migration itself.
Managing access risk through a RISE migration requires three things:
CERPASS is SAP-native - built on SAP BTP and HANA - which means it plugs directly into your S/4HANA environment without additional infrastructure.
With CERPASS, organisations migrating via RISE get:
Implementation in days. No separate GRC platform required. Available via the SAP Store.
Does RISE with SAP include access control?
No. SAP manages the infrastructure and platform. Access control - including role design, SoD management, and compliance reporting - remains the customer's responsibility.
Should we clean up access before or after migration?
Before. Carrying existing conflicts into S/4HANA makes remediation significantly more complex and costly. A pre-migration access review is always the better approach.
Does S/4HANA change our existing SoD ruleset?
Yes. S/4HANA introduces new transaction codes, authorisation objects, and business processes that require an updated ruleset. Your ECC ruleset is a starting point, not a finished product.
Can CERPASS be implemented during a RISE migration project?
Yes. CERPASS is SAP-native and can be deployed alongside your S/4HANA implementation, giving you access control from go-live rather than as an afterthought. CERPASS is also now certified for clean core on the SAP BTP.
RISE gives you a modern, cloud-based SAP environment. What it does not give you is clean access control. That is your responsibility - and the window to get it right is during the migration, not after.
Want to know what your access risk looks like heading into RISE - or coming out of it? Request an assessment and we will show you where you stand.
👉 Request a demo | sales@cerpasssoftware.com
CERPASS® is SAP-certified and available via the SAP Store. #simpleGRC