Gaining Control Over Cross-System Access Risks

Industry: Financial Services
Challenge: Cross-System Segregation of Duties (SoD) Monitoring
Solution: KPMG Sofy Access Management
The ChallengeAs the organization expanded its technology landscape, critical business processes became distributed across multiple ERP and business applications. While access rights were managed within individual systems, visibility of risks across applications was limited.

This created a significant challenge: users could accumulate access rights across systems that, when combined, resulted in Segregation of Duties conflicts that were invisible when reviewing systems individually. Identifying these conflicts required extensive manual analysis, making continuous monitoring nearly impossible.

The organization needed a scalable way to:

  • Monitor SoD conflicts across multiple business-critical applications
  • Improve transparency over user access rights
  • Reduce manual effort in access reviews and investigations
  • Demonstrate effective control to auditors and stakeholders

The Solution

The organization selected KPMG Sofy Access Management to establish a centralized and automated approach to access risk management.

Using Sofy’s cross-system monitoring capabilities, access rights from multiple applications were combined into a single analysis platform. The solution enabled the organization to identify conflicts that spanned different systems, automate risk detection, and gain full visibility into critical access risks. This approach was supported by KPMG’s best-practice SoD rulesets and risk models.

Sofy’s root-cause analysis capabilities allowed access risks to be traced back to the exact roles, permissions, and combinations of access rights responsible for the conflict. This significantly accelerated remediation activities and improved collaboration between business and IT teams.

The Results

The implementation delivered immediate and measurable benefits:

  • Complete visibility of SoD conflicts across the IT landscape
  • Automated monitoring of access risks across multiple applications
  • Faster identification and remediation of high-risk conflicts
  • Reduced manual effort in access reviews and investigations
  • Improved audit readiness and compliance reporting
  • A sustainable framework for continuous access risk monitoring

By moving from manual reviews to continuous monitoring, the organization gained greater confidence in its access control environment while significantly reducing the effort required to stay compliant.

Key Benefits Delivered by Sofy

  • Cross-system SoD monitoring across ERP and non-ERP applications
  • Automated identification of access risks and critical access
  • Deep root-cause analysis down to permission level
  • Out-of-the-box KPMG best-practice rulesets
  • Continuous monitoring and risk response workflows
  • Scalable framework supporting future application onboarding

Customer Outcome

“By implementing Sofy Access Management, the organization transformed a highly manual and fragmented access risk process into a centralized, automated, and continuously monitored control environment. The result was better visibility, faster remediation, and improved

Related articles

How a pension fund digitized Risk Management and Strengthened Compliance

Client Story

How a pension fund digitized Risk Management and Strengthened Compliance

Read more
How AkzoNobel Strengthened Compliance with Continuous Control Monitoring

Client Story

How AkzoNobel Strengthened Compliance with Continuous Control Monitoring

Read more