MTC Skopos is an SAP SoD analysis tool built for audit work. It tests a client's access against a ruleset you control rather than the one configured inside their GRC system, traces every conflict to the authorization objects and field values that cause it, and exports each result table straight into the audit file. A 10,000-user system analyzes in under 2 minutes on a standard laptop, so remediation claims can be re-tested before reporting. Licensing is a flat €5,736/year and one license covers every engagement in the year, with no per-client fee.

MTC Skopos for audit work
Basis for the findingYour ruleset, not the client's configured exclusions and mitigations
Analysis depthAuthorization-object and field-value level, not transaction codes alone
Evidence outputRisk register, per-user and per-role findings, did-do evidence, Excel/CSV workpapers
Re-testingUnder 2 minutes for 10,000 users, so remediation claims can be confirmed in-engagement
Works without client toolingYes, identical depth whether or not the client owns a GRC suite
Included ruleset350+ SoD risks, 700+ critical access checks, 100+ authorization quality checks, all editable
License modelFlat €5,736/year, €555 per additional seat, no per-client or per-system fees

Why bring your own SoD tool to an engagement?

If the client has SAP GRC or a similar suite, you can ask them to run the reports for you. Two things limit that. The report reflects their ruleset, which means every exclusion, mitigating control and risk acceptance they configured is already baked into the output you are meant to be testing. And a great many clients have no GRC tooling at all, which leaves SoD testing to hand-sampling a few users.

Testing with your own analyzer removes both problems. You get the same depth on any SAP system regardless of what the client owns, and the ruleset behind the finding is one you can defend in the file. For a market overview of what else is available, see the 13 SAP SoD tools comparison.

The practical part of working this way, the table exports and the offline run, is covered on the SoD analysis without production access page.

What audit evidence does it produce?

A point-in-time analysis gives you:

  • SoD conflict findings per user and per role, traced to the exact authorization objects and values that create the conflict, not just the transaction codes. This is the difference between a finding a role owner accepts and one they spend a week disputing
  • Critical access findings: who can use SU01, SE38, SCC4, SM59, debug, or any sensitive access you define
  • Did-do evidence: whether users holding conflicting access actually executed both sides, which separates theoretical exposure from exercised risk and usually changes what goes in the report
  • Exportable workpapers: every result table exports to Excel or CSV for the audit file

The authorization-level versus transaction-level distinction is worth understanding before the first engagement, because it is the most common reason a client challenges a SoD finding.

How does the engagement rhythm work?

From receiving the exports to first findings is under 15 minutes, since a full analysis of a 10,000-user system runs in under 2 minutes on a standard laptop. Reviewing the first-pass risk picture takes about an hour. A realistic engagement looks like this:

  1. Before fieldwork: send the client the extraction guide
  2. Day 1: load the exports, run the full analysis, review the risk register
  3. Fieldwork: drill into findings, gather did-do evidence, discuss with process owners
  4. Before reporting: re-run against a fresh export to confirm any remediation the client claims to have performed

That last step is the one that is usually impossible. When a full run costs two minutes rather than a scheduled batch window, verifying a remediation claim stops being a next-year problem.

What does it cost across multiple clients?

One flat license: from €5,736 per year for the base license, additional seats at €555 per seat per year, optional modules priced openly in the configurator. There are no per-client, per-user or per-system fees, so the same license covers every audit you run in the year rather than being priced against the size of each client's landscape. Pricing is public and configurable on the pricing section, with a 14-day trial to test the workflow on a real engagement. The complete model is on the SAP SoD tool pricing page.

Frequently asked questions

Why test SAP access with your own tool instead of the client's GRC reports?

Because a client-run report reflects the client's own ruleset, including every mitigation and exclusion they configured. Testing with a ruleset you control gives you an independent basis for the finding, and it works identically whether the client owns a GRC suite or nothing at all. It also removes the dependency on the client scheduling a batch run for you.

What audit evidence does an SoD analysis produce?

Per-user and per-role conflict findings traced to the authorization objects and field values that create the conflict rather than to transaction codes alone, critical access findings for sensitive transactions you define, did-do evidence showing whether the conflicting access was actually executed, and every result table exportable to Excel or CSV for the audit file.

Can I re-test a remediation claim during the engagement?

Yes, and this is where analysis speed stops being a vanity metric. A full run on a 10,000-user system takes under 2 minutes on a standard laptop, so when a client says a finding is fixed you can load a fresh export and confirm it before reporting instead of taking the claim on trust.

Can I test against my own audit firm's SoD ruleset?

Yes. You can start from the included template ruleset (350+ SoD risks, 700+ critical access checks, and 100+ authorization quality checks), import the client's ruleset to test their own stated controls, or bring your firm's risk catalog. Rulesets are editable down to authorization-object level, reusable across engagements, and convertible to SAP GRC format.

How much does MTC Skopos cost for audit work?

Licensing starts at €5,736 per year for the base license, with additional seats at €555 per seat per year and optional add-on modules priced openly in the configurator. There are no per-client, per-user, or per-system fees, so one license covers every engagement you run in the year. A 14-day trial is available.


Related reading: SoD analysis without production access · SAP Access Risk Analysis · Did-Do Analysis explained · Authorization-level vs transaction-level analysis · SoD tool for consultants