Leading SAP GRC Tools: 2026

sailpoint
Location: Denver, Colorado, USA, with European offices in Germany and Belgium.
VC Funding: Raised 0 million in a Series B growth round in December 2025 led by KKR, with Sixth Street Growth, TenEleven and existing investor Carrick Capital Partners taking part. The round valued the company at about billion.

Overview: Pathlock started life in 2004 as Greenlight Technologies. In May 2022 it merged with Appsian, Security Weaver, CSI Tools and SAST Solutions, which is why the product covers so much ground. The platform combines access governance, compliant provisioning, user access reviews, firefighter access, continuous controls monitoring, data masking and application security in one place, with connectors to more than 140 applications. Its Dynamic Access Control runs natively on the SAP ABAP server and enforces policies on data attributes such as country code or material group rather than roles alone. SAP has certified the suite as clean core compatible for RISE with SAP.
Three things have pushed this category forward in the last two years. The move to S/4HANA and SAP Cloud ERP Private (formerly RISE with SAP) changed user licensing to a Full Use Equivalent model, where a user’s classification is driven by the authorisations assigned to them, so bad role design now shows up on the invoice and not just in the audit report. SAP Identity Management is heading for the end of its maintenance window in 2027, which is prompting a lot of SAP teams to pick a replacement rather than defer the decision. And mainstream maintenance for SAP’s own GRC 12.0, Access Control included, is set to end on December 31st, 2027, with the successor built on SAP HANA. Every Access Control customer now has a migration to plan, and every vendor in this list knows it.
Many large organisations run their finance, procurement and supply chain on SAP, which means the software sitting around SAP decides who can approve a payment, who can create a vendor, and who can quietly do both. That is the job these five products do. They handle access risk, segregation of duties, user provisioning, role design and, increasingly, how many user licenses you are actually paying for.
VC Funding: Around 0 million raised, with Vertica Capital Partners as the main backer. Damon Tompkins was appointed CEO in January 2026.
The split here is between depth and breadth. Soterion and Xiting are SAP specialists, and that shows in how their tools handle SAP’s own quirks, from FUE license classification to ABAP role design. Pathlock sits in the middle, native inside SAP but built to cover the applications around it. SailPoint and Saviynt come at SAP from the identity side, which is the right call if SAP is one of many systems you have to certify access for, and more than you need if it is the only one that matters.

Best for: Enterprises that need SAP governed inside a single identity programme covering every other system too.
saviynt
Below are five vendors working in this space in 2026, with what each one is actually good at, who owns or funds them, and the kind of buyer they suit. Two are SAP specialists, one is an SAP specialist that also runs a consulting practice, and two are broader identity platforms that treat SAP as an important application.
Overview: Soterion builds GRC and SAP licensing software for companies running SAP. Its Access Risk Manager reports segregation of duties and sensitive access risk in plain business language rather than transaction codes, which is the point: the people signing off on access are often finance and operations managers, not SAP security specialists. The SAP License Manager analyses actual system usage to help work out the number of FUE licenses needed, and a What-If Simulator lets an approver see the license cost of an access change before granting it. It ships as on-premise software, a SaaS product, or a managed service for teams without in-house GRC skills.
Best for: Organisations facing an SAP role redesign or an S/4HANA authorisation rebuild who want consultants and tooling from the same vendor, especially in the DACH region.

Overview: Saviynt sells a converged identity platform: identity governance, privileged access management, application access governance and identity security posture management in one cloud product. For SAP customers the draw is application access governance, which brings cross-application segregation of duties analysis into the same tool that handles the rest of the estate. The company says it works with more than 20 percent of the Fortune 100, and named customers include Levi’s, Kraft Heinz and Western Digital. Like SailPoint, it is now pushing hard on machine and AI agent identities, which was the stated reason for the KKR round.
Best for: Companies replacing several separate identity and access tools with one platform, particularly if privileged access is in scope.
xiting
Overview: Xiting sits between software vendor and consultancy. Its main product, the Xiting Authorizations Management Suite (XAMS), handles SAP role design and rebuilding, role testing, ABAP custom code vulnerability scanning and the creation of security concept documentation, which is the part most teams dread. The tools are SAP certified and the company holds SAP Gold Partner status, with more than 700 customers. Alongside the software it runs authorisation redesign projects, IAM work and security monitoring, so buyers usually get the tooling and the people together.
Location: Johannesburg, South Africa, with regional teams covering EMEA, DACH, ANZ and North America.

Location: Schöfflisdorf near Zurich, Switzerland, with subsidiaries in Germany, the UK, Romania and the United States.
Best for: Mid-sized and large SAP customers who want access risk reporting the business can read, and anyone trying to get their FUE count under control before a renewal.
Overview: SailPoint is an identity governance company rather than an SAP company, but it is one route large organisations use to govern SAP access as part of a wider identity programme. Identity Security Cloud is the SaaS platform, IdentityIQ the self-hosted option, and both handle joiner-mover-leaver automation, access certifications and policy enforcement across thousands of applications. Recent moves have gone after non-human identity: it bought Imprivata’s identity governance business in December 2024, acquired Tel Aviv-based Entro Security in June 2026, and launched Agentic Fabric in May 2026 to govern AI agents. SAP-specific risk analysis is handled through connectors and partners rather than deep native ABAP tooling.
Best for: Large enterprises running SAP alongside Oracle, Workday, Salesforce and others, that want one control platform instead of five.
VC Funding: Publicly traded on Nasdaq under SAIL. Previously owned by Thoma Bravo, it returned to the market in February 2025 at a share, raising roughly .2 billion.

Location: El Segundo, California, USA, with regional offices in London, Amsterdam, Dubai, Singapore and India.
Budget and team size decide most of it. A company with a two-person SAP security team and an auditor asking about segregation of duties needs something the business can actually operate, and a billion identity platform is not that. A global bank with SAP, Oracle and 200 SaaS applications has the opposite problem. Check three things before you shortlist. Whether the vendor’s SAP risk rule set can be customised to your processes. Whether the tool reports on license consumption as well as risk, since under the FUE model those are now the same conversation. And what the vendor’s answer is for SAP Access Control customers after 2027, because if they cannot describe that migration clearly they have not thought about the next two years as hard as you are about to.
soterion
VC Funding: Privately held. Founded as a GmbH in June 2008 by a group of SAP consultants and converted to an AG in May 2010. Around 140 employees.
VC Funding: Privately held. Founded in 2011 by Dudley Cartwright, who is still CEO.

Which one should you choose?

Location: Austin, Texas, USA.
pathlock

Similar Posts