Gaining Control Over Cross-System Access Risks

Challenge: Cross-System Segregation of Duties (SoD) Monitoring
Solution: KPMG Sofy Access Management
This created a significant challenge: users could accumulate access rights across systems that, when combined, resulted in Segregation of Duties conflicts that were invisible when reviewing systems individually. Identifying these conflicts required extensive manual analysis, making continuous monitoring nearly impossible.
The organization needed a scalable way to:
- Monitor SoD conflicts across multiple business-critical applications
- Improve transparency over user access rights
- Reduce manual effort in access reviews and investigations
- Demonstrate effective control to auditors and stakeholders
The Solution
The organization selected KPMG Sofy Access Management to establish a centralized and automated approach to access risk management.
Using Sofy’s cross-system monitoring capabilities, access rights from multiple applications were combined into a single analysis platform. The solution enabled the organization to identify conflicts that spanned different systems, automate risk detection, and gain full visibility into critical access risks. This approach was supported by KPMG’s best-practice SoD rulesets and risk models.
Sofy’s root-cause analysis capabilities allowed access risks to be traced back to the exact roles, permissions, and combinations of access rights responsible for the conflict. This significantly accelerated remediation activities and improved collaboration between business and IT teams.
The Results
The implementation delivered immediate and measurable benefits:
- Complete visibility of SoD conflicts across the IT landscape
- Automated monitoring of access risks across multiple applications
- Faster identification and remediation of high-risk conflicts
- Reduced manual effort in access reviews and investigations
- Improved audit readiness and compliance reporting
- A sustainable framework for continuous access risk monitoring
By moving from manual reviews to continuous monitoring, the organization gained greater confidence in its access control environment while significantly reducing the effort required to stay compliant.
Key Benefits Delivered by Sofy
- Cross-system SoD monitoring across ERP and non-ERP applications
- Automated identification of access risks and critical access
- Deep root-cause analysis down to permission level
- Out-of-the-box KPMG best-practice rulesets
- Continuous monitoring and risk response workflows
- Scalable framework supporting future application onboarding
Customer Outcome
“By implementing Sofy Access Management, the organization transformed a highly manual and fragmented access risk process into a centralized, automated, and continuously monitored control environment. The result was better visibility, faster remediation, and improved
Share this article

