Meet the Authors

Key Takeaways What you need to know
  1. Pathlock and KPMG are targeting SAP access governance as AI agents, automation and cloud transformation expand the number of human and non-human identities interacting with core systems.

  2. The alliance combines Pathlock’s identity and transaction controls with KPMG’s cybersecurity, compliance, risk and SAP transformation advisory capabilities.

  3. SAP leaders will need continuous access controls and stronger audit evidence as AI-enabled workflows take on finance, procurement, payroll and other sensitive business processes.

Pathlock and KPMG LLP announced on August 3 an alliance aimed at helping large enterprises govern identity security and access risk across complex, multi-application environments as they modernize core business systems. Pathlock said the relationship will focus on enterprises running billions of dollars of transactions through ERP and other business-critical systems.

The alliance brings together Pathlock’s identity and access governance platform with KPMG’s cybersecurity, compliance, risk, and transformation advisory capabilities. The announcement lands at a time when SAP modernization is expanding the access-governance challenge. Cloud migrations, application consolidation, AI agents, automation, and business-process redesign can all change who or what can access sensitive workflows, approve transactions, elevate privileges, and create audit exposure.

Identity Controls Move into Transformation

The alliance is structured around joint execution. Pathlock said that when KPMG works with clients on SAP risk transformation or technology modernization, Pathlock can become part of the solution for identity security and access risk management.

Explore related questions

KPMG brings experience across regulatory and compliance domains including SOX, HIPAA, PCI DSS, and GDPR. That gives the alliance a clear audit-readiness angle: organizations need access governance that can support transformation without forcing control evidence, risk analysis, and compliance monitoring into manual after-the-fact work.

Mick McGarry, Principal, Cybersecurity Services at KPMG LLP, said the firm is focused on helping clients use AI while maintaining cybersecurity resilience. He said combining identity governance with behavioral insights and cybersecurity frameworks can help organizations manage access and transaction risk.

Damon Tompkins, CEO of Pathlock, said the alliance brings together KPMG’s compliance, risk, and transformation expertise with Pathlock’s technology to help organizations modernize identity access and governance programs with cost savings and confidence.

As businesses move from static roles and periodic access reviews toward continuous controls and AI-supported monitoring, governance needs to account for both human and non-human identities. Pathlock said its platform is used by Global 2000 organizations running complex SAP, Oracle, and Workday environments, and is built to govern every identity and every transaction at scale.

AI Governance Starts with SAP Access

The Pathlock-KPMG alliance shows why AI governance is becoming inseparable from SAP access governance. As organizations introduce AI agents and automated processes into core systems, the question is not only what a model can generate. It is what connected agents, users, and workflows are allowed to do inside controlled business processes.

That is especially relevant for finance and audit teams. If AI-enabled tools are used to support close, procurement, payroll, compliance, invoice processing, or controls testing, companies need visibility into permissions, transactions, exceptions, elevated access, and control violations. A governance model that stops at the application boundary will miss much of the operational risk.

The practical value of the alliance will depend on execution. Enterprises will need to see how Pathlock’s controls and analytics fit into KPMG-led transformation programs, how quickly access-risk insights can be operationalized, and whether the combination reduces audit burden without creating another governance silo.

What This Means for SAPinsiders

  • Access governance belongs inside SAP transformation planning. Modernization programs often focus first on platform selection, data migration, integrations, and process redesign, but access risk can undermine all of those workstreams if it is treated as a late-stage control exercise. SAP program leaders, CISOs, and audit teams need to build identity governance into the transformation roadmap from the start.
  • AI agents raise the stakes for transaction-level controls. As non-human identities begin acting across business systems, organizations need to know which actions they can take, which controls apply, and how exceptions are detected. Security and GRC leaders should expect SAP access policies to become more dynamic, behavioral, and evidence-driven.
  • Audit readiness is becoming a technology architecture issue. Manual reviews and periodic control checks cannot keep pace with continuous business change, cloud migrations, and agentic automation. For systems integrators, advisory firms, and vendors, the opportunity is to connect identity, controls, monitoring, and audit evidence directly into the application environment rather than bolt them on after go-live.

A version of this article was first published by ERP Today on August 5, 2026. 

Events

15Oct
SAPinsider Summit Philadelphia 2026Philadelphia, PA, United States
View All