GOVERNANCEGRC_SOD

Services / Governance & Supply

Governance, Risk, Compliance & SoD

Controls that live in a policy document are not controls. We design the risk and control matrix, translate it into system roles, and prove enforcement with evidence your auditors and your board can both read.

Practice
Governance & Supply
Best fit
Best fit ahead of an audit, alongside an ERP go-live, or after an incident that a control should have caught.
Industries
Manufacturing · Distribution · Healthcare · Education · Retail · Professional Services

What’s included

Scope, stated before we start

Six work-streams that make up a standard engagement. Anything outside them is priced separately and named in the proposal — never absorbed quietly.

Risk & control matrix

Process-level risks mapped to preventive and detective controls, with owner, frequency and evidence source stated for each one.

Segregation-of-duties design

A conflict matrix across create/approve/pay, master-data maintenance and reconciliation, mapped down to actual ERP permissions rather than job titles.

Role redesign & remediation

Rebuilt role definitions that remove conflicts, plus documented compensating controls where headcount makes full separation genuinely impossible.

Continuous control monitoring

Automated exception reports — duplicate vendors, out-of-policy approvals, bank-detail changes, backdated entries — routed to owners on a schedule.

Policy & delegation of authority

Approval thresholds and a delegation-of-authority schedule written so that what the policy says and what the system enforces are the same thing.

Audit readiness pack

Control descriptions, walkthrough evidence, access-review records and a remediation tracker — assembled once and maintained, not rebuilt each audit.

Outcomes

What changes when this is done properly

These are the three differences clients describe six months after go-live — not feature claims.

  • SoD conflicts identified and closed at permission level
  • Exceptions monitored continuously, not sampled annually
  • Audit evidence assembled before it is requested

Not sure this is the right service? Discover is a fixed-price, two-to-three week assessment that answers the question with evidence — and it is usable whether or not you appoint us. Start there instead →

Who it’s for

Industries where this comes up most

Each links to how the service is shaped for that sector — the requirements differ more than vendors admit.

Our approach

The same four phases, applied to this scope

Reused deliberately. A consistent method is what makes a fixed price honest and a date holdable.

01

Discover

Process mapping before software selection.

We walk the floor and the ledger. Two to three weeks of structured interviews and document tracing produce a current-state process map, a data-quality baseline, and a written list of the decisions your systems cannot currently answer.

02

Design

One target architecture, agreed on paper.

Chart of accounts, item and customer master rules, approval hierarchies, integration contracts and reporting model are designed together — not discovered during build. You sign off a blueprint, not a demo.

03

Deliver

Configure, migrate, test, train — in that order.

Iterative configuration with fortnightly conference-room pilots. Data migration runs three times before go-live: trial, dry run, and cutover, each reconciled to the closing trial balance. Users train on their own data.

04

Sustain

Hypercare, then measurable adoption.

Four to eight weeks of hypercare with named owners and a burn-down of issues. Then a governance rhythm: master-data stewardship, monthly close review, and a Power BI adoption dashboard that shows whether the system is actually being used.

Related case study

Product costing the shop floor actually recognises

SAP_B120 weeks2025

Standard costs that had drifted for years rebuilt against real routings and consumption, with shop-floor capture on rugged terminals and variance reported per production order.

Our board finally reads the same numbers we do. Month-end reporting dropped from eleven working days to four, and nobody rebuilds a spreadsheet to get there.
IT Director · Multi-plant engineering manufacturer
99%+Inventory accuracy, from 82%
6hrsFloor-to-ledger lag, from 2 days
11ptsMargin variance explained

FAQ

Questions we are asked before signing

Something not covered? Ask us directly →

Then we design compensating controls and document them: independent review of a defined exception report, dual authorisation on high-value payments, and periodic reperformance. Auditors accept designed compensation; they do not accept silence.

We design and remediate. We are not your statutory auditor, which is precisely why we can rebuild the roles and controls rather than only reporting on them.

COSO for the control framework, ISO 27001 for information security, and the specific requirements of your regulator or group policy. We map to what you are actually held to, without ceremony.

Four to six months to design, remediate and generate a period of evidence. Starting six weeks out gets you a documented plan and honest disclosure — better than nothing, but not the same thing.

Next step

Talk to someone who has implemented GRC & SoD before

Not a sales call. A working conversation with the person who would run the engagement, and a straight answer on scope, sequence and cost.

WhatsApp