Why Manufacturing Auditors Keep Finding the Same Access Control Gaps — and What the IT Team Missed
Author : Tushar Pansare | Published On : 06 Aug 2026
The audit finding arrives and it is not a surprise to the IT team. They knew the orphaned accounts were there. They knew the SAP role combinations were creating conflicts. What they did not have was a governance architecture that could surface, document, and remediate those conflicts across every system the auditor was going to test.
That gap between what the IT team knows exists and what the governance tooling can actually prove is where manufacturing compliance programs fail. And it fails in a predictable way, for a structural reason most compliance conversations never address directly.
The Multi-System Reality Manufacturing Governance Tools Were Not Built For
Manufacturing companies run SAP for core operations: procurement, production, finance, HR. SAP is where the financially material transactions happen and where auditors testing SOX ITGC, IFC, or COBIT focus first. The compliance tooling typically reflects this. SAP GRC governs SAP access. The SoD rule set covers SAP transactions. The certification campaigns run inside the SAP boundary.
The problem is that the auditor does not stop at the SAP boundary.
The same employees who hold SAP roles also have access to Microsoft 365, Entra ID, ServiceNow, Salesforce, and Workday. Admin access in ServiceNow from someone who moved to a different role six months ago. Privileged roles in Entra ID from employees who left the company entirely. The access that creates the audit finding is often not the SAP conflict the governance tool was watching. It is the access outside the SAP boundary that no governance tool was watching at all.
The result is a patchwork of access controls that looks complete from inside each individual system and looks fragmented from the auditor's perspective. Each finding is individually explainable. Together they form a pattern that signals a governance architecture problem, not a configuration problem.
What Auditors Actually Test in Manufacturing Environments
Regardless of the specific framework, whether SOX ITGC, IFC, or COBIT, the controls auditors test in manufacturing environments fall into three categories.
The first is high-risk SoD controls. No single individual should be able to complete a financially material transaction without independent oversight. Vendor creation plus payment approval. Journal entry plus posting authorization. Purchase order creation plus goods receipt plus invoice verification. These are the conflicts that create fraud opportunity, and auditors look for them systematically across every system where financially sensitive functions exist.
The second is joiner-mover-leaver lifecycle controls. New users should be provisioned promptly with appropriate access. Role changes from HR events should be reflected in system access immediately. Leavers should have access revoked without delay. And evidence showing when each change occurred and what triggered it must be available in a format the auditor can read and verify.
The third is periodic access certifications. Managers must periodically review and confirm that their direct reports' access remains appropriate for their current role and responsibilities. The certifications must be documented, acted on, and evidenced in a format that survives audit scrutiny.
Most manufacturing compliance programs handle the first category reasonably well for SAP. The second and third categories, particularly across systems beyond SAP, are where the audit findings accumulate.
The SAP GRC Gap Nobody Talks About
SAP GRC is a well-designed tool for what it was built to do: govern access control within the SAP environment. Organizations with mature SAP GRC deployments have robust SoD detection and remediation within SAP. This is genuinely valuable and genuinely important.
What SAP GRC was not designed for is governing the identity lifecycle. It does not automate provisioning and revocation across SAP and connected systems when an HR event occurs in SuccessFactors. It does not run access certification campaigns that include Microsoft 365, Entra ID, and ServiceNow alongside SAP. It does not produce a unified violation report that shows an auditor the complete access risk picture across the manufacturing IT landscape.
When an employee leaves the organization, the HR event in SuccessFactors needs to trigger access revocation in SAP, Entra ID, ServiceNow, Salesforce, and every other connected system simultaneously, with a timestamped audit trail showing when each revocation occurred. SAP GRC handles the SAP piece. The rest requires a governance layer that operates above the individual system boundaries.
This is the architecture gap that produces the audit findings. Not inadequate SAP governance. Governance that stops at the SAP boundary while the auditor's scope does not.
What Closed-Loop Manufacturing Identity Governance Requires
Closing this gap requires governance that operates across the complete manufacturing IT landscape from a single platform, with a single unified violation report, and a single access certification campaign that covers every connected system.
SoD rule sets need to cover not just SAP financial and operational modules but also the basis and system administration layer, the HR and payroll layer, and the plant maintenance layer where OEM compliance risk lives. Each rule needs to be written not just as a technical configuration but as a plain-language description of what could actually happen if the conflict is exploited. A fraud scenario that the CFO and audit committee can read, not just the SAP Basis team.
Identity lifecycle automation needs to connect HR system events directly to provisioning and revocation across every connected system simultaneously. When SuccessFactors records a leaver event, access should terminate across SAP, Entra ID, ServiceNow, and every other connected application in the same automated workflow, with a single timestamped audit trail.
Access certification campaigns need to run across all connected systems in a single campaign, with manager approvals and revocations recorded in a format that exports directly to the evidence package the auditor requests.
When these three elements operate from a single platform rather than from separate tools with separate records, the governance architecture produces a unified compliance picture that matches the scope of the auditor's review.
The Question Worth Asking Before the Next Audit
Before the next audit cycle begins, one diagnostic reveals whether the current governance architecture covers the full scope the auditor will test.
Pull the list of employees who left the organization in the past twelve months. Check whether their access was revoked in SAP. Then check Entra ID. Then ServiceNow. Then every other connected system. The gap between the SAP revocation record and the complete revocation record across all systems is the gap the auditor will find.
Manufacturing companies that close that gap before the audit do not eliminate audit findings. They change what the auditor finds from a governance architecture problem to individual exceptions, which is a fundamentally different conversation to have in the audit room.
For more on governing the complete manufacturing IT landscape across SAP, Microsoft, ServiceNow, and Workday from a single platform, visit openiam.com/solutions/manufacturing
