Meet the Speakers

Solving the SoD and user administration challenge for human and agentic actors

As SOX compliance expectations rise, many organizations still lack complete visibility and control over who — and what — has access to critical SAP and SOX-relevant enterprise applications. The root issue is structural. Enterprise IAM is designed to manage identity at scale, but SOX requires access governance to operate as a financial control system aligned to financial reporting risk and audit defensibility. In modern landscapes where financial processes run across multiple systems, access can appear compliant within individual applications while still introducing material risk across the end-to-end workflow. KPMG’s most recent material weakness study underscores the point: among companies disclosing material weaknesses, 56% cited IT, software, security, and access issues — and 43% cited segregation of duties or control design weaknesses.

These control gaps drive a rising cost of compliance. The 2025 KPMG SOX Survey reports an FY24 average program effort of 15,580 hours, with 45% of organizations reporting year-over-year cost increases. When access governance is weak by design, teams compensate with manual controls, spreadsheet-driven reviews, late-cycle remediation, and repeated audit retesting — creating friction across Finance, IT, IAM, and Internal Audit. This session addresses the identity and access breakdowns that repeatedly surface in audits: disconnected joiner-mover-leaver processes that create access creep, SoD conflicts that don’t map cleanly to financial workflows across applications, privileged access that isn’t governed as a repeatable auditable control, and high-volume user access reviews that generate evidence but limited assurance. We’ll also address a fast-growing blind spot: the lifecycle and governance of non-human identities — service accounts, bots, and automation agents — interacting with SOX systems without consistent ownership or enforceable boundaries. The session will include a live demonstration of how identity discovery, access governance, and continuous compliance monitoring can be automated across SAP and adjacent applications using a modern identity security platform.
Saviynt
Register now to learn:

  • How to identify and close cross-application identity gaps that create SOX exposure across SAP and beyond
  • How to reduce the cost of compliance by shifting from manual reviews and repeated remediation cycles to sustainable, risk-aligned access governance
  • How to extend governance to non-human identities and AI agents interacting with SOX applications to reduce audit risk and improve control defensibility

Sponsored by:

Explore related questions