CERPASS Blog

RISE with SAP: Your Roles Are Migrated - But Are Your Risks?

Written by Marcel Blokland | Sep 8, 2026, 11:04:27 AM

Migrating to SAP S/4HANA via RISE is a major step forward. But does your access control keep pace? In this blog we explain what access risks come with RISE migrations - and how to ensure your roles and controls are as clean as your new environment.

What is RISE with SAP - and what does it mean for access control?

RISE with SAP is SAP's Business Transformation as a Service offering: a structured path to migrate your on-premise SAP ERP to SAP S/4HANA Cloud. It promises cleaner processes, lower infrastructure costs, and a future-proof platform.

What it does not promise is clean access control. Cloud migration does not transfer accountability for SAP security outcomes to SAP. If required customer-side controls are not implemented and maintained, the organisation bears the risk.

That is the part many organisations discover too late.

What access risks does RISE with SAP migration introduce?

Migration projects move fast. Deadlines are tight, workstreams run in parallel, and access design is rarely the top priority. The result is predictable: during migrations, roles are upgraded to meet deadlines. New access combinations are introduced but not understood. Risk laden combinations survive go-live.

Common access risks that emerge during and after RISE migration:

  • Inherited SoD conflicts: existing role conflicts carried forward from ECC without review
  • Role proliferation: users accumulate access across old and new roles during security uplift

  • New S/4HANA risk combinations: S/4HANA introduces new authorisation objects and business processes that create conflicts that did not exist in ECC

Many organisations still approach the transition as a lift-and-shift exercise. Access models are carried forward with the expectation they can be addressed later. Under cloud operating models, that delay becomes a liability.

Why access risk is harder to spot post-migration?

A 2025 SAPinsider Research Report revealed that 23% of organisations reported experiencing a cybersecurity attack that impacted their SAP environment in the past year. Migrations are a peak vulnerability window - systems are in flux, governance models are under pressure, and nobody has a complete picture of who has access to what.

Excessive user access increases the risk of fraud, operational inefficiency, and compliance exposure — all at a moment when your organisation is already stretched by the migration itself.

What good access control looks like during and after RISE?

Managing access risk through a RISE migration requires three things:

  • A clean ruleset before go-live: define which access combinations are unacceptable in S/4HANA before you migrate. Do not carry ECC conflicts into your new environment.
  • Access Risk Analysis (ARA) at go-live: run a full conflict scan the moment your S/4HANA system goes live. Know exactly where you stand from day one.
  • Continuous dashboards post-migration: access risk does not stop at go-live. Monitor continuously as roles evolve and users are onboarded.

How CERPASS supports RISE with SAP migrations?

CERPASS is SAP-native - built on SAP BTP and HANA - which means it plugs directly into your S/4HANA environment without additional infrastructure.

With CERPASS, organisations migrating via RISE get:

  • Risk Ruleset: a maintained set of conflict rules tailored to S/4HANA processes
  • Access Risk Analysis: automated access risk analysis from day one post-migration
  • Dashboards and Reports: continuous visibility for both IT and Finance stakeholders

Implementation in days. No separate GRC platform required. Available via the SAP Store.

Frequently asked questions about RISE with SAP and access control

Does RISE with SAP include access control?
No. SAP manages the infrastructure and platform. Access control - including role design, SoD management, and compliance reporting - remains the customer's responsibility.

Should we clean up access before or after migration?
Before. Carrying existing conflicts into S/4HANA makes remediation significantly more complex and costly. A pre-migration access review is always the better approach.

Does S/4HANA change our existing SoD ruleset?
Yes. S/4HANA introduces new transaction codes, authorisation objects, and business processes that require an updated ruleset. Your ECC ruleset is a starting point, not a finished product.

Can CERPASS be implemented during a RISE migration project?
Yes. CERPASS is SAP-native and can be deployed alongside your S/4HANA implementation, giving you access control from go-live rather than as an afterthought. CERPASS is also now certified for clean core on the SAP BTP.

Conclusion: 'clean core' is not the same as 'clean access'

RISE gives you a modern, cloud-based SAP environment. What it does not give you is clean access control. That is your responsibility - and the window to get it right is during the migration, not after.

Want to know what your access risk looks like heading into RISE - or coming out of it? Request an assessment and we will show you where you stand.

👉 Request a demo | sales@cerpasssoftware.com

CERPASS® is SAP-certified and available via the SAP Store. #simpleGRC