Meet the Authors

Key Takeaways What you need to know
  1. RISE with SAP migrations are shifting from an infrastructure-first project to a governance-first SAP cloud transformation, because access risk, segregation-of-duties conflicts, and provisioning controls now affect value realization, compliance, and adoption outcomes. This change impacts SAP program managers, CIOs, enterprise architects, and GRC leaders planning SAP S/4HANA migration.

  2. Customer Advisory Group’s Project Rise shows that Identity and Access Governance (IAG) and SAP S/4HANA Access Control should be implemented during the RISE with SAP transition, not after go-live. This matters because redesigning roles early helps prevent audit findings, orphaned access, and remediation delays that can slow SAP cloud deployment.

  3. SAP’s new focus on customer value, consumption, and realized outcomes makes access governance a business issue, not just an audit requirement, for organizations moving to SAP S/4HANA in the cloud. SAP leaders, security teams, and compliance stakeholders need early GRC advisory support, continuous monitoring, and vendor-independent access governance planning to protect the business case.

Most RISE with SAP migrations get sold on infrastructure and total cost of ownership. The governance conversation shows up late, usually after the first audit finding. That gap is exactly where the Customer Advisory Group (CAG) has planted its flag, and it is one worth SAP leaders’ attention in 2026.

CAG is not a global systems integrator. It is a focused SAP Silver Partner, founded in 2012, built specifically around Governance, Risk and Compliance (GRC) and Security, with more than 400 hands-on engagements and roots that trace back to Virsa Systems, the access-control pioneer SAP acquired in 2006. That lineage matters. It means CAG has been living inside SAP’s GRC stack since before GRC was a product line. In March 2026, the firm carried that expertise onto the GRC track at Pathlock Innovation Days, a virtual global event held on March 30.

The center of gravity, though, is CAG’s SAP-endorsed offering: Project Rise, Resilient Access Governance for the Transition to the Cloud.

Explore related questions

A Quick Starter Model For Access Governance

CAG’s Project Rise is a partnership with SAP to implement Identity and Access Governance (IAG) and SAP S/4HANA Access Control as organizations move to the cloud, building what the firm calls a comprehensive access control and governance model. The offering is packaged as Quick Start programs aimed at identifying key risks, sustaining governance, developing a compliance roadmap, and maintaining access control and monitoring during periods of change.

The technical footprint is specific, not generic. SAP’s own COE senior management names CAG as a partner with purpose-built implementation offerings for Identity and Access Governance (IAG), Single Sign-On (SSO), Enterprise Threat Detection (ETD), Greenlight Access Violation Management (AVM), and strategic advisory and roadmap assessments. CAG also runs implementation services for Pathlock AVM, which connects its GRC practice to the broader access-violation and continuous-controls tooling ecosystem.

Governance Becomes The Currency For Value Realization

SAPinsider’s March 2026 reporting on SAP’s leadership restructuring points to a real shift in how the vendor now defines success. SAP created a Customer Value Group and appointed Thomas Saueressig as chief customer officer, unifying Customer Success and Customer Services & Delivery under one Board area effective April 1. The stated intent is to emphasize consumption, expansion, and realized value over simple license volume, pushing account teams, partners, and customers to align earlier on measurable outcomes and adoption metrics.

Read that against a cloud migration, and the implication is direct. In a world where SAP measures partners and customers on realized value rather than go-live dates, unresolved access risk is a drag on the value story. Segregation-of-duties conflicts, orphaned roles, and weak provisioning controls slow adoption, trigger remediation cycles, and undercut the outcome metrics SAP now wants to see. CAG’s argument that access governance must be redesigned during the transition rather than bolted on afterward aligns with the direction SAP itself is heading.

The identity surface also changes shape in the cloud. Moving to SAP S/4HANA through RISE with SAP reshapes how roles, provisioning, and monitoring work, and a redesign is often the honest response rather than a lift-and-shift of legacy roles. That is precisely the problem CAG’s IAG plus SAP S/4HANA Access Control model is built to solve.

What This Means for SAPinsiders

Access governance belongs in the RISE business case, not the post-go-live cleanup. CAG’s Project Rise exists because access risk surfaces during transition, and SAP’s new value-realization posture makes that risk commercially visible, not merely a compliance line item. Program managers running RISE with SAP should pull GRC and security into scoping from the first workshop, map segregation-of-duties and provisioning risks against the target SAP S/4HANA role design before cutover, and treat a specialist such as CAG as an early-phase advisor rather than a remediation vendor called in after the audit.

Treat the SAP S/4HANA move as a mandate to redesign roles. Lifting legacy ECC roles into SAP S/4HANA carries old segregation-of-duties conflicts into a new environment and buries them under a cloud narrative. Enterprise architects should use the transition to rebuild the access model around IAG and SAP S/4HANA Access Control, using quick-start assessments to establish a clean baseline, then wiring in continuous monitoring through tooling such as Pathlock AVM so the design does not decay after go-live.

Vendor-independent GRC advice is worth more as the SAP security portfolio widens. CAG positions itself on vendor-independent recommendations, deep GRC lineage from the Virsa era, and senior-only consultants. As SAP’s security and compliance surface expands across IAG, SSO, ETD, and third-party controls like AVM, CIOs face genuine tool-selection complexity. Bringing in an advisor without a software-license incentive and validating that independence against the specific IAG and Access Control roadmap helps ensure architecture decisions serve the compliance posture rather than a vendor’s sales play.

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All