What we do · SAP Technology
SAP Technology · Boxes printed
What we do·SAP Technology

SAP Technology

Cyber, business process and architecture across the landscape most audit functions stop at the edge of.

What actually breaks

The audit plan stops at the edge of the landscape.

Almost every internal audit function has SAP in its universe and almost none audits it properly. The reason is rarely judgement — it is that opening a landscape needs basis, security and process knowledge in the same room at the same time, and that combination is expensive to keep on a bench that only needs it twice a year.

So the SAP audit becomes an access review, or an ITGC audit with SAP in the title, and the configuration that actually enforces the control is never opened. The finding rate on a real SAP audit is the evidence for this, and it is why this area exists as a separate shelf rather than a line in a technology audit.

The comparison

Bought as a project. Delivered as a product.

Neither column is a caricature. The left is how this work is bought almost everywhere, including by people who dislike it.

How this is normally bought
An access review, described as an SAP audit
A conflict ruleset accepted as the vendor shipped it
Findings written as risks, with no path to a fix
Remediation scheduled without reference to your basis calendar
How it works here
Configuration tested as configured — parameters, gateway, RFC, transport routes
The ruleset validated against your processes, then tested against real assignments
Every finding mapped to the note or parameter that closes it
Sequenced against your release and transport calendar, so fixes can actually be deployed
The schedule

Six to eight weeks, depending on the landscape.

An SAP engagement, week by week. Longer than a process audit because the extraction alone is a week when it is done properly.

Week 1
Extraction and scope lock

Roles, profiles, parameters and transport history extracted, and the control points agreed against what the data shows.

Partner gate
Weeks 2–5
Configuration and conflict testing

Tested in the system, not in a document — including the conflicts that only appear when real assignments meet real transactions.

Week 6
Findings and peer review

Conflicts ranked by transactional exposure rather than by count, then peer-reviewed.

Partner gate
Weeks 7–8
Report and readout

Findings mapped to their fix, sequenced against your release calendar.

Partner gate
Why it repeats

A rare bench, on a printed price.

The scarcity is real and we do not pretend otherwise. What we refuse to do is price the scarcity differently each time it is asked for.

4
engagements covering one landscape
2
kinds of knowledge in the room — basis and process
18
credits per SoD control point, published
1
formula, the same as every other area

Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth, including what we hold back and why, on the method page.

Inside this area

One landscape, four angles.

Most audit plans stop at the edge of SAP, and the reason is usually bench rather than judgment: opening a landscape needs basis, security and process knowledge in the same room. These four engagements cover the security configuration, the process configuration, the architecture underneath, and the segregation-of-duties ruleset that ties them together.

Engagements

12 engagements, every box printed.

Tap any one to read its scope box — what we analyze, how scope gets chosen, what is tested, what the report contains, and what the remediation plan does and doesn’t include. Prices come from one published formula.

Family A · Assurance

Assurance — an opinion your Audit Committee can rely on. Bought by the Chief Audit Executive.

A1  SoD by Business Process Detailed Assessment — 40 control points, 40 SoD · 780 credits · $39,000 +
The box780 credits · $39,000
  • 01Role and authorization mining — every role, profile and composite in scope mapped to the business processes it actually touches
  • 02Ruleset build or validation — your conflict ruleset tested against the process, not accepted as delivered
  • 0340 conflict rules tested — each traced to real assignments and real transactions, not theoretical exposure
  • 04Mitigating control assessment — every accepted conflict checked for a control that genuinely operates
  • 05Remediation plan — conflicts ranked by transactional exposure, not by count
Count agreed at scope lock, before fieldworkThe formula never moves
A2  SAP Cyber Detailed Assessment — 55 control points, 10 SoD · 890 credits · $44,500 +
The box890 credits · $44,500
  • 01Landscape and exposure review — every system in the landscape, its patch state, and what is reachable from where
  • 02Security configuration testing — profile parameters, gateway and RFC security, secure communications
  • 0355 control points tested — authentication, privileged and emergency access, interface security, logging, 10 SoD points on security administration
  • 04Final report — findings mapped to the SAP note or parameter that fixes them
  • 05Remediation plan — sequenced against your SAP release and basis calendar
Count agreed at scope lock, before fieldworkThe formula never moves
A3  SAP GRC Detailed Audit — 50 control points, 10 SoD · 830 credits · $41,500 +
The box830 credits · $41,500
  • 01GRC platform and module review — Access Control, Process Control and Risk Management as configured, against how the design documents say they were meant to run
  • 02Ruleset and risk-analysis integrity — whether the rules in force actually detect the conflicts they claim to, tested against real assignments rather than against the shipped catalogue
  • 0350 control points tested — connector and synchronisation health, workflow and approval routing, emergency access provisioning and log review, mitigation-control operation, and 10 segregation-of-duties points on the administration of the platform itself
  • 04Final report — every finding evidenced from the system, with the conflicts the platform is currently failing to surface named rather than summarized
  • 05Remediation plan — platform configuration fixes separated from ruleset fixes and from process fixes, since all three have different owners
Count agreed at scope lock, before fieldworkThe formula never moves

Where Signify has configured your GRC platform under A12 we cannot run this — assurance over a platform we built is not assurance. A5 reviews the ruleset alone and carries no audit opinion.

A4  SAP Technology Architecture Detailed Assessment — 45 control points, 5 SoD · 740 credits · $37,000 +
The box740 credits · $37,000
  • 01Architecture review — landscape design, transport routes, interfaces and integration patterns
  • 02Change and transport control testing — the path from development to production, tested for what can bypass it
  • 0345 control points tested — basis administration, transport management, interface governance, backup and recovery, 5 SoD points on basis access
  • 04Final report — with the architectural risks no single control owner is accountable for, named
  • 05Remediation plan — sequenced to survive your upgrade roadmap
Count agreed at scope lock, before fieldworkThe formula never moves

Family C · Function build

Function build — your own function’s infrastructure.

A6  Controls Design Integration — P2P — procure-to-pay · 1000 credits · $50,000 +
The box1000 credits · $50,000
  • 01Control objectives agreed for the cycle — what the controls must achieve, signed off before anything is configured
  • 02Design of the control set — preventive and detective, automated where SAP can carry them, manual only where it genuinely cannot
  • 03Configuration specified and integrated — tolerance settings, release strategies, three-way-match rules, blocked-invoice handling and the SoD ruleset for the cycle
  • 04Design walkthrough and evidence of operation — each control demonstrated running in your system, not described in a deck
  • 05Control catalogue handed over — owners named, evidence sources identified, ready for whoever audits it next
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not an audit. Because we design these controls, we cannot later audit this cycle or its segregation of duties.

A7  Controls Design Integration — O2C — order-to-cash · 1200 credits · $60,000 +
The box1200 credits · $60,000
  • 01Control objectives agreed for the cycle — signed off before anything is configured
  • 02Design of the control set — credit limits, pricing and discount authorization, delivery and billing block rules, revenue cut-off
  • 03Configuration specified and integrated — including the SoD ruleset for the cycle
  • 04Design walkthrough and evidence of operation — each control demonstrated running in your system
  • 05Control catalogue handed over — owners named, evidence sources identified
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not an audit. Because we design these controls, we cannot later audit this cycle or its segregation of duties.

A8  Controls Design Integration — R2R — record-to-report · 1300 credits · $65,000 +
The box1300 credits · $65,000
  • 01Control objectives agreed for the cycle — signed off before anything is configured
  • 02Design of the control set — journal authorization and posting rules, account reconciliation cadence, period-close checklist, consolidation and intercompany
  • 03Configuration specified and integrated — including the SoD ruleset for the cycle
  • 04Design walkthrough and evidence of operation — each control demonstrated running in your system
  • 05Control catalogue handed over — owners named, evidence sources identified
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not an audit. Because we design these controls, we cannot later audit this cycle or its segregation of duties.

A9  Controls Design Integration — Payroll — hire-to-retire · 800 credits · $40,000 +
The box800 credits · $40,000
  • 01Control objectives agreed for the cycle — signed off before anything is configured
  • 02Design of the control set — master-data change authorization, payrun approval and exception review, off-cycle payment handling, termination triggers
  • 03Configuration specified and integrated — including the SoD ruleset for the cycle
  • 04Design walkthrough and evidence of operation — each control demonstrated running in your system
  • 05Control catalogue handed over — owners named, evidence sources identified
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not an audit. Because we design these controls, we cannot later audit this cycle or its segregation of duties.

A10  Controls Design Integration — Technology & Security Controls — technology and security · 800 credits · $40,000 +
The box800 credits · $40,000
  • 01Control objectives agreed for the layer — what the technical and security controls must achieve, signed off before anything is configured
  • 02Design of the control set — profile parameters, privileged and emergency access, interface and RFC security, logging and monitoring, automated wherever SAP can carry them
  • 03Configuration specified and integrated — including the SoD ruleset covering security administration
  • 04Design walkthrough and evidence of operation — each control demonstrated running in your system, not described in a deck
  • 05Control catalogue handed over — owners named, evidence sources identified
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not a detailed assessment. Because we design these controls, we cannot later provide assurance over this layer or its segregation of duties.

A11  Controls Design Integration — Materials Management — materials management · 1300 credits · $65,000 +
The box1300 credits · $65,000
  • 01Control objectives agreed for the cycle — signed off before anything is configured
  • 02Design of the control set — material-master governance, goods movement and reservation authorisation, physical inventory and cycle-count controls, valuation and price-change approval
  • 03Configuration specified and integrated — movement-type restrictions, tolerance settings and the SoD ruleset for the cycle
  • 04Design walkthrough and evidence of operation — each control demonstrated running in your system
  • 05Control catalogue handed over — owners named, evidence sources identified
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not a detailed assessment. Because we design these controls, we cannot later provide assurance over this cycle or its segregation of duties.

A12  Controls Design Integration — SAP GRC — GRC Modules · 800 credits · $40,000 +
The box800 credits · $40,000
  • 01Control objectives agreed for access governance — what the GRC platform must enforce, signed off before configuration
  • 02Design of the control set — Access Control workflows, risk analysis and mitigation, emergency access management, periodic user-access review and role provisioning
  • 03Configuration specified and integrated — connectors, rule engine and the mitigation-control catalogue
  • 04Design walkthrough and evidence of operation — each workflow demonstrated running in your system
  • 05Control catalogue handed over — owners named, evidence sources identified
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not a detailed assessment. Because we configure this platform, we cannot later provide assurance over it.

Family B · Assessment

Assessment — a diagnostic, no assurance opinion. Bought by the function’s own head, except where the item is a procedure.

A5  SAP GRC Ruleset Review — ~1 ruleset · 580 credits · $29,000 +
The box580 credits · $29,000
  • 01Ruleset baseline — the shipped ruleset compared against what your landscape actually runs, module by module
  • 02Risk and function coverage tested — which risks the ruleset detects, which it silently misses, and which fire so often they are ignored
  • 03False-positive analysis — mitigations, exclusions and org-level rules reviewed against real conflict data from your own system
  • 04Recommended ruleset changes — specified to the risk-ID level, ready to load rather than described in principle
  • 05Findings reporta detailed assessment, not an audit; no assurance opinion is expressed
Count agreed at scope lock, before fieldworkThe formula never moves

We review the ruleset; where we go on to configure it, that is a build and forecloses assurance over it.

Anything here can join a plan built in any other area — a penetration test can sit inside an internal audit year. Build a plan →

Bought as a bundle

SAP Landscape Assurance

Four engagements across one SAP estate — SoD, cyber, GRC and order-to-cash. Segregation of duties, cyber exposure and the GRC platform across your SAP estate, plus the order-to-cash cycle that runs on top of it.

Composition
A1 · A2 · A3 · D5
Credits
3,400 cr
At base rate
$170,000

Same engagements, same menu prices — buying the block as a year changes nothing except that it is worth buying at once. Read the full card, including what it forecloses →

What we do · SAP Technology

One thing worth knowing before you buy.

Every recurring service we run forecloses the assurance over it. If we keep your framework alive we cannot audit it, and if we audit it we cannot keep it alive. You choose which, we print the consequence before you buy rather than after, and where an Audit Committee relationship already exists we protect it.