{{item.title}}
{{item.text}}
Download PDF - {{item.damSize}}
{{item.text}}
Running SAP GRC Access Control in-house is complex and costly. Specialist expertise is scarce, operational responsibility often rests with a small number of people, and access risks are becoming more significant as cyber threats grow. With the Access Control Service, PwC manages the technical operations of SAP GRC Edition for HANA 1.0. We manage the functional processes with you, using a standardised, audit-ready and predictable service model.
Maintenance for SAP GRC Access Control 12 ends in 2027. Organisations that have not migrated to SAP GRC Edition for HANA 1.0 by then will no longer receive security updates or compliance support, with direct consequences for audit readiness and operational risk. At the same time, the move to SAP RISE licensing is fundamentally changing the cost structure for operations and licensing. Planning your migration early helps you avoid time pressure and security gaps. We help you identify the right time to make the transition.
“For many organisations, operating SAP GRC AC in-house is neither cost-effective nor future-ready. Our Managed Services offer a clear alternative: efficient, scalable and audit-ready.”
We operate SAP GRC Edition for HANA 1.0 in a secure PwC cloud environment based on SAP RISE and connect it to your SAP systems. Data is separated through a client structure. System updates, support packages, patches and changes are covered by the service, tested and documented. You use the solution; we take responsibility for operating it.
We continuously monitor operations, resolve incidents efficiently and document all activities transparently. Standardised support processes, regular reporting and flexible additional services provide reliable service quality. This frees your authorisation team to focus on analysing and remediating identified risks.
You have access to preconfigured, audit-ready processes, including access risk analysis, access requests, emergency access and user lifecycle processes. If an audit identifies findings relating to GRC processes, we help you respond to queries and prepare evidence using a standardised approach.
We use a standardised, one-off onboarding process to move you from your current system to our SAP GRC AC for HANA 1.0 instances. Relevant data is transferred to the defined processes, decisions are made about which data to retain, and your rule set is loaded. If required, we update your existing rule set or align it with the PwC standard to support an efficient and secure start to the Managed Services.
We offer our Managed Services for a predictable monthly fee, supplemented by one-off onboarding costs.
Our modular approach allows you to select the services that fit your needs. In addition to technical operations and functional support, options include assessing risks from Firefighter emergency access, continuously updating and calibrating your access risk rule set, and supporting the annual recertification of access rights.
Operating SAP GRC Access Control in-house costs between €200,000 and €300,000 a year for infrastructure, patches and development. RISE changes this model: technical operations become part of licence costs and are tied to SAP pricing, including annual increases, while an individual customer has limited negotiating power. We bundle operations and licensing into a predictable fee and pass on the benefits of our scale on to you. Our technical operations also cover integrations and synchronisation specific to SAP GRC Access Control.
SAP GRC expertise is scarce, costly and often concentrated among a small number of key people. At the same time, SAP Basis and GRC operations take up valuable internal capacity.
With PwC Managed Services, we take full responsibility for technical operations and support key elements of functional process management through an experienced team of specialist. Standardised processes provide high-quality documentation, efficient support and continuous development of your GRC landscape.
Auditors and other reviewers increasingly expect detailed evidence on segregation of duties (SoD) and access risks. Access risks are also becoming more important in the context of cyber security. The effort required to document controls and prepare evidence is often underestimated. As auditors, we understand what reviewers need. We provide audit-ready processes and work with you to prepare the supporting evidence.
With maintenance for SAP GRC AC 12 ending on 31 December 2027, a technical migration is unavoidable. You can carry out the migration independently, but it will still require testing and functional support. Migrating to our service also involves an one-off effort, but we validate the processes for you. The move to S/4HANA also requires a redesign of your access risk rule set. As part of the platform migration, we align your rule set with our standardised framework to deliver additional value.