Agenda
03.12.2026
14:00 - 14:45
Session Announcement Coming Soon
Referenten
Markus Schumacher
Beschreibung
Session Details Coming Soon.
14:45 - 15:30
A GRC solution does not fail because risks exist — it fails when the business does not see them early enough
Referenten
Andreas Knab
Soterion
Beschreibung
In many organisations, access risks remain hidden in IT reports, while the people approving access lack a clear business view.
- In cloud and FUE-based licensing models, poor access decisions can become direct cost decisions. Unnecessary roles, unused authorisations and over-approved access can quickly translate into avoidable license exposure.
- The real challenge is not having more GRC functionality, but making risk understandable for the business. Business users need clear, practical guidance before they approve access — not after costs or audit findings appear.
- Modern GRC must connect access risk, business ownership and license impact. A usable, business-centric approach helps organisations prevent unnecessary risks and costs before they are built into the authorisation landscape.
15:30 - 16:15
SAP’s New Authorization-Based Licensing: What It Means for Authorization Administrators
Beschreibung
- Get an overview of SAP’s shift to authorization-based licensing, its implications and the standard capabilities within SAP S/4HANA Core that support administrators.
- Learn how state-of-the-art least-privilege access concepts can reduce licensing risks and unexpected cost impacts.
- Identify potential risks in overly generous authorization assignments under the new model.
- Understand why license-driven role adjustments must align with your authorization concept — security and functionality should never be compromised for cost savings.
16:15 - 17:00
Maximize the Potential of Your Risk Analysis Tool
Referenten
Adam Edwards
Convista Consulting Ltd
Bianca Folkerts
Convista Consulting Ltd
Beschreibung
The presentation will discuss ideas on how an organization can benefit from using their risk analysis tool beyond its core function of identifying regulatory risks, such as:
- Supporting Data Owners to identify who has access to the data they are responsible for
- Define “Need to know” info when creating Roles
- Supporting Risk based recertification of Roles.
Bitte beachten Sie, dass die Agenda Änderungen unterliegt.