What is Segregation of Duties in SAP - and how do you manage SoD conflicts without drowning in manual work? In this blog I explain what SoD means, where conflicts hide, and what effective control looks like in practice.
Segregation of Duties (SoD) is a fundamental internal control principle: no single person should have end-to-end control over a critical business process. The goal is to prevent both intentional fraud and unintentional errors by splitting conflicting responsibilities across different users or roles.
In SAP, SoD means distributing access rights so that no single user can execute conflicting duties - duties that together could enable fraud or error to go undetected. If an SAP user can both create a vendor and make payments, they could create a fictitious vendor and pay themselves. That is exactly the kind of risk SoD is designed to prevent.
Most SoD conflicts are not the result of bad intentions - they develop over time. Common causes include overlapping responsibilities, poor role design, emergency access that is never revoked, and business changes such as mergers or reorganisations that leave outdated access in place.
Classic high-risk combinations in SAP include:
Even if each individual role looks acceptable in isolation, the combination of roles assigned to a user can create hidden SoD conflicts — conflicts that only surface when the auditor arrives.
In most SAP environments, access rights accumulate over time. Employees move between roles, take on temporary responsibilities, and inherit permissions that were never revoked. This is sometimes called privilege creep - and it is one of the most common root causes of SoD violations.
Migrating to S/4HANA is not just a technical upgrade - it is a moment when many organisations, often for the first time in years, take a holistic look at their access design. S/4HANA introduces new approval workflows, a centralised Business Partner model, and cross-module integrations that significantly change the existing SoD matrix. Roles that were acceptable in ECC may create new conflicts in S/4HANA.
Spreadsheets cannot keep pace. Manual reviews happen too infrequently. And the consequences of getting it wrong are significant: audit findings and penalties, reputational damage, fraud and financial loss, and operational inefficiency from detecting and correcting misuse.
Managing SoD is not a one-time project. It is an ongoing control. Three things make it work:
CERPASS is a SAP-native access control solution built for organisations that want control over SoD risk - without the complexity and cost of a full GRC platform.
With CERPASS, IT and security teams get:
No separate infrastructure. No lengthy implementation. SAP-native and available via the SAP Store.
What is the difference between an SoD conflict and a critical access risk?
An SoD conflict involves two or more access rights that together create a risk. A critical access risk is a single access right that is dangerous on its own - for example, the ability to delete audit logs or reset passwords without approval.
How often should you run an SoD analysis in SAP?
Continuously - not just before an audit. Every role change, new hire, or system update can introduce new conflicts. Automated, real-time analysis is the only way to stay ahead of accumulating risk.
Does SoD management change with S/4HANA?
Yes. S/4HANA introduces new business processes, new authorisation objects, and cross-system integrations that require a revised SoD matrix. Organisations migrating from ECC should treat the migration as an opportunity to redesign access from the ground up.
Can CERPASS detect cross-system SoD conflicts?
CERPASS focuses on SAP-native environments and provides deep SoD analysis within your SAP landscape. For cross-system scenarios, contact us to discuss your specific setup.
SoD conflicts do not appear once and disappear. They grow with every role change, every new hire, and every system update. Managing them effectively requires automation and continuous visibility - not manual effort and annual spreadsheet reviews.
Want to know where your SoD conflicts are right now? Book a conversation and we will show you in your own SAP environment.
👉 Book a demo | sales@cerpasssoftware.com
CERPASS® is SAP-certified and available via the SAP Store. #simpleGRC