SAP GRC Access Control as a Managed Service

Your expert for questions

Martin Krause
Director at PwC Germany
Tel: +49 171 7670881
Email

Access compliance without in-house operations. Control without complexity. 

Run SAP GRC Access Control with confidence, without building your own specialist team 

Running SAP GRC Access Control in-house is complex and costly. Specialist expertise is scarce, operational responsibility often rests with a small number of people, and access risks are becoming more significant as cyber threats grow. With the Access Control Service, PwC manages the technical operations of SAP GRC Edition for HANA 1.0. We manage the functional processes with you, using a standardised, audit-ready and predictable service model. 

Why act now? Support for SAP GRC AC 12 ends in 2027

Maintenance for SAP GRC Access Control 12 ends in 2027. Organisations that have not migrated to SAP GRC Edition for HANA 1.0 by then will no longer receive security updates or compliance support, with direct consequences for audit readiness and operational risk. At the same time, the move to SAP RISE licensing is fundamentally changing the cost structure for operations and licensing. Planning your migration early helps you avoid time pressure and security gaps. We help you identify the right time to make the transition. 

SAP GRC (Governance, Risk and Compliance) helps organisations manage risks, meet regulatory requirements and maintain internal controls, particularly for access rights in SAP systems. SAP GRC Access Control manages and monitors authorisations. 

PwC’s Access Control Service addresses these challenges in single step. We operate SAP GRC Edition for HANA 1.0 for you in the SAP RISE environment and connect your SAP systems. Standardised processes and materials create efficiencies, further enhanced by our experience as auditors. 

“For many organisations, operating SAP GRC AC in-house is neither cost-effective nor future-ready. Our Managed Services offer a clear alternative: efficient, scalable and audit-ready.”

Martin Krause,Director at PwC Germany

Free quick check for your SAP GRC Access Control strategy

Platform operations in the PwC SAP RISE cloud 

We operate SAP GRC Edition for HANA 1.0 in a secure PwC cloud environment based on SAP RISE and connect it to your SAP systems. Data is separated through a client structure. System updates, support packages, patches and changes are covered by the service, tested and documented. You use the solution; we take responsibility for operating it.

Proactive monitoring and support 

We continuously monitor operations, resolve incidents efficiently and document all activities transparently. Standardised support processes, regular reporting and flexible additional services provide reliable service quality. This frees your authorisation team to focus on analysing and remediating identified risks. 

Standardised core processes and administration 

You have access to preconfigured, audit-ready processes, including access risk analysis, access requests, emergency access and user lifecycle processes. If an audit identifies findings relating to GRC processes, we help you respond to queries and prepare evidence using a standardised approach. 

Onboarding and migration 

We use a standardised, one-off onboarding process to move you from your current system to our SAP GRC AC for HANA 1.0 instances. Relevant data is transferred to the defined processes, decisions are made about which data to retain, and your rule set is loaded. If required, we update your existing rule set or align it with the PwC standard to support an efficient and secure start to the Managed Services. 

Modular service model 

We offer our Managed Services for a predictable monthly fee, supplemented by one-off onboarding costs.

Our modular approach allows you to select the services that fit your needs. In addition to technical operations and functional support, options include assessing risks from Firefighter emergency access, continuously updating and calibrating your access risk rule set, and supporting the annual recertification of access rights. 

Request your GRC quick check

Gain clarity on costs, migration and your target state in just a few days.

The hidden cost of your current GRC operations

GRC licences and technical operations

Operating SAP GRC Access Control in-house costs between €200,000 and €300,000 a year for infrastructure, patches and development. RISE changes this model: technical operations become part of licence costs and are tied to SAP pricing, including annual increases, while an individual customer has limited negotiating power. We bundle operations and licensing into a predictable fee and pass on the benefits of our scale on to you. Our technical operations also cover integrations and synchronisation specific to SAP GRC Access Control.

Core resources and consultants

SAP GRC expertise is scarce, costly and often concentrated among a small number of key people. At the same time, SAP Basis and GRC operations take up valuable internal capacity. 

With PwC Managed Services, we take full responsibility for technical operations and support key elements of functional process management through an experienced team of specialist. Standardised processes provide high-quality documentation, efficient support and continuous development of your GRC landscape.

Audit documentation and evidence preparation

Auditors and other reviewers increasingly expect detailed evidence on segregation of duties (SoD) and access risks. Access risks are also becoming more important in the context of cyber security. The effort required to document controls and prepare evidence is often underestimated. As auditors, we understand what reviewers need. We provide audit-ready processes and work with you to prepare the supporting evidence. 

Technical migration to SAP GRC Access Control for SAP HANA 1.0

With maintenance for SAP GRC AC 12 ending on 31 December 2027, a technical migration is unavoidable. You can carry out the migration independently, but it will still require testing and functional support. Migrating to our service also involves an one-off effort, but we validate the processes for you. The move to S/4HANA also requires a redesign of your access risk rule set. As part of the platform migration, we align your rule set with our standardised framework to deliver additional value. 

Frequently asked questions 

You retain the functional decisions, including approving access requests, assessing risks case by case and defining your business requirements. We manage operations, maintenance and monitoring. You continue to implement authorisation roles and remediate identified risks. Typically, this reduces internal effort by 30 to 40%, particularly during periods of intensive system use. Your specialists can spend the time saved resolving conflicts rather than completing repetitive tasks or troubleshooting synchronisation issues. We can also support these activities as an additional service. 

You can use either your own rule set or the established PwC rule set, which we maintain and update continuously. The PwC rule set includes current rules for S/4HANA and Fiori but is not tailored to your specific processes. If required, we can take over and integrate your existing rule set. As part of the transition, we carry out a one-off quality review and identify potential weaknesses. We can also support you with an additional proactive service to improve your ruleset while ensuring that it is continuously kept up to date based on the latest PwC ruleset. 

Our aim is to provide a standardised GRC Access Control solution that remains close to the standard product. We cannot take over custom developments because the system is shared with other clients. Processes can be adapted using the available customising and configuration options. During onboarding, we work with you to assess your current processes. 

Additional services include assessing risks from Firefighter emergency access, regularly updating and calibrating your access risk rule set, and supporting the annual recertification of access rights. We also offer a range of consulting services. If you need something different or would like us to take on additional responsibilities, please contact us. 

We operate SAP GRC AC Edition for HANA 1.0 in a secure PwC cloud environment based on SAP RISE and connect your SAP production, test or development systems using standard connectors and plug-ins. Your system landscape remains under your responsibility, including maintenance of the plug-ins, although we can support you. Separate clients fully segregate your SAP GRC Access Control data from that of other customers. 

We integrate our environment securely into your architecture. 

The service includes integration with one identity source and with your email provider for sending notifications. 

Offboarding is defined in the contract from the outset and follows a structured process. We provide the complete data from your GRC environment, including the rule set, current configurations and all historical data, such as assignments and approvals, in a documented, audit-ready format. We help you maintain a complete audit trail for auditors and other reviewers. 

Follow us

Contact us

Martin  Krause

Martin Krause

Director, PwC Germany

Tel: +49 171 7670881

Paul Muschiol

Paul Muschiol

Senior Manager, PwC Germany

Tel: +49 151 26652863

Hide