Meet the Experts
Governance, Risk, and Compliance (GRC) in SAP environments has been about managing user access, enforcing internal controls, assessing corporate risk, and streamlining audits. However, that mandate is expanding to include the governance of artificial intelligence (AI) usage and solutions, something for which GRC teams may not be entirely prepared. This points to 2026 being an inflection year. The technical and financial foundations of GRC have caught up to the ambition organizations expressed a year ago, while structural governance and native SAP tooling have not kept pace with that momentum. Understanding both sides of the story, the acceleration and the lag, is essential for any organization planning GRC investment through 2027.
This year’s benchmark report tells a story of uneven but real progress. Budgets are up, integration has leapt forward, identity and access governance has moved to the center of GRC strategy, and organizations are assessing their own maturity more honestly. At the same time, native SAP GRC tooling adoption remains fragmented, formal data privacy governance is eroding even as technical controls improve, and the risk agenda is shifting toward transformation risk faster than most governance structures are adapting to match it.
Organizations reporting their financial systems as fully integrated with risk and compliance data for real-time insight jumped from this year. Organizations describing their GRC systems as fully integrated enterprise-wide across departments also rose. And the sourcing model itself polarized: fully in-house SAP GRC management increased. Organizations are not drifting toward integration incrementally; they are committing to it. They are also committing more decisively to one sourcing model or the other rather than sitting in the hybrid middle.
Download the benchmark report to read a deeper analysis and receive insight on your own plans.
– Understand how GRC and risk intelligence is being funded in the year ahead.
– Explore the tools and technologies being used for GRC and risk intelligence.
– Learn about the change in data privacy governance structures and understand the importance of that change.
– See what SAPinsiders are doing to pivot risk priorities towards transformation.



