← Back to Controls

APP-08

Layer:
Application
Category:
Access to Programs and Data
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 29, 2026

Control Description

Access request workflows in SAP GRC are configured to perform automated Segregation of Duties (SoD) checks against a defined ruleset, with flagged conflicts requiring authorized management approval prior to provisioning.

Risk

Failure to enforce SoD controls during the access provisioning process may allow users to obtain conflicting access rights (e.g., ability to create and approve transactions, or initiate and approve changes), resulting in inadequate segregation of duties, unauthorized transactions, fraudulent activity, or circumvention of critical controls.

Implementation Details

• Ruleset Configuration: SAP GRC Access Control is configured with a comprehensive, risk-based SoD ruleset (mapping regulatory and internal organizational policies) stored in backend tables such as GRACSODRISKRS (risk-to-rule mapping) and GRACSODRISK (risk definitions and active flags).

• Workflow Parameter Enforcement: The system configuration parameter governing real-time risk checks during request submission (typically under SPRO path GRC -> Access Control -> Maintain Configuration Settings for "Risk Analysis - Access Request") is explicitly activated—setting the parameter value for "Enable risk analysis upon request submission" to ASYNCHRONOUS (or SYNCHRONOUS) to ensure automated interception.

• Management Mitigation Workflow: When an access request introduces a segregation of duties conflict, the GRC workflow automatically flags the violation and blocks automated provisioning, routing the request to designated risk owners or management for documented mitigation approval or access rejection.

Test Procedures

A) Test of Design (ToD):

• Ruleset Verification (Test 1): Via transaction SE16, query table GRACSODRISKRS to identify active SoD risks mapped to the corporate ruleset. Query table GRACSODRISK to review risk descriptions and confirm that the Active Flag is enabled.

• Configuration Inspection Navigate to SPRO -> GRC -> Access Control -> Maintain Configuration Settings, scroll to Risk Analysis - Access Request, and verify that the parameter "Enable risk analysis upon request submission" is set to active (e.g., ASYNCHRONOUS).

B) Test of Operating Effectiveness (ToE):

• Submit a test access request in SAP GRC for an SAP S/4HANA target system containing known conflicting roles/actions. Verify that the system automatically executes an SoD check upon submission, successfully flags the violation, and prevents provisioning until proper management review or mitigation approval is obtained.