RegRisk unifies enterprise risk, controls, audit, segregation of duties and vendor risk on a single register — and reads your ERP directly, so a failed control test and an SoD violation roll up to the same board-level score.
Remove Supplier Maintenance from the AP Manager role; assign it to the Vendor Data duty instead.
Least-disruptive — affects 3 users, no approval-path change. Simulated: resolves 3/3, adds 0 new conflicts.
rule · SOD-P2P-014role · AP Managersource · Fusion sync 06:35
Audit trailempty
No decisions recorded in this session. Approve, edit or reject the proposal above and the entry is written here.
011
GRC modules, one register
0+8+
ERP & SaaS connectors
06
AI agents, human-approved
0h48h
To first SoD finding
02 · The register
Every risk sits in one cell of one matrix
Likelihood × impact, scored by the model in Master Setup. A failed control test and an SoD violation roll up to the same board-level score.
Likelihood
L5
L4
L3
L2
L1
I1I2I3I4I5
Impact
Low 1–4Medium 5–9High 10–16Critical 17–25
Filtered register9 of 9
All plotted risks
9 plotted · 41 monitored
Hover or arrow through the grid to read a cell; select one to filter the register to it.
residual · across all cells
SOD-P2P-014 sits at L4 × I5 · score 20 · critical. Approving the fix above re-scores it here.
Residual scores across 41 monitored risks · updated on last ERP sync. Risk titles are held in the tenant, not in this public view.
03 · The data model
One data model for the entire GRC lifecycle
Risks, controls, tests, issues, incidents, policies, entitlements and vendors are all objects in the same register. Four verbs, one source of truth.
01 / GOVERN
Govern
Risk taxonomy, hierarchy, appetite, policies and board reporting in one governance layer.
02 / ASSESS
Assess
RCSA cycles, likelihood × impact scoring, control design and testing across every business unit.
03 / DETECT
Detect
Continuous monitoring of KRIs, SoD conflicts, sensitive access and control failures — not quarterly sampling.
04 / RESPOND
Respond
Issues, incidents and remediation plans tracked to closure, with a full evidence trail for the auditor.
04 · Modules
Eleven modules. Licence what you need.
The data model is shared from day one, so every module you add makes the others richer. Select one to see which agents operate on it and which connectors feed it.
Cross-links
Select a module to see the agents scoped to it and the connectors that feed it. The cross-links are the point: modules are not separate products.
05 · Agents
Six agents that do the work — not just summarise it
Each agent is scoped to a module, grounded in your own register, and gated by human approval. They propose; your team disposes.
Workers, security groups, domains, business processes
Q3 2026
Microsoft Dynamics 365
F&O · CE
Users, security roles, duties, privileges
Q3 2026
Salesforce
Sales · Service
Users, profiles, permission sets, object access
Q4 2026
Entra ID · Okta · Ariba · Coupa
Identity · S2P
Identity, group membership, joiner-mover-leaver events
Roadmap
Sync jobs run on schedule or on demand — with completion tracking, delta detection and a full run history per profile. Readiness uses the same four-step scale as severity.
We built where the reference customers are. E-Business Suite leads, then NetSuite and Fusion Cloud — with the rest of the estate close behind.
Readiness
Family
Showing 8 of 8 connectors
The connector our customers reach for first. It reads the full EBS authorisation model — responsibilities, menus, functions and request groups — and maps it into RegRisk's normalised user–role–entitlement model, so SoD analysis runs against live access rather than a stale extract.
What RegRisk ingests
UsersResponsibilitiesMenusFunctionsRequest groupsData groupsOrg accessOperating units
Connection
Read-only DB account / SOA
Sync
Scheduled + on-demand
Refresh
Full, then delta
First result
< 48 hours
Footprint
None on prod servers
Pulls the NetSuite permission model — roles, permission levels, subsidiaries and approval routing — for SoD and access review across a multi-subsidiary footprint.
Reads Fusion’s role hierarchy end to end — roles, duty roles, privileges and data access sets — so a conflict traces from a user right down to the duty role that causes it.
The first run is recorded here when it completes. Run it again to add another line.
How a sync works
Connector to dashboard, every stage observable
Each sync job records its start, end and completion percentage — with a full run history per profile, exactly like the console above.
01
Connect
Read-only, credential-scoped account per application.
→
02
Sync job
Scheduled or on-demand, with completion tracking.
→
03
Normalise
Vendor objects mapped to one user–role–entitlement model.
→
04
Rules & agents
SoD rules, KRI thresholds and agent analysis run on it.
→
05
Dashboards
Findings surface in the SoD dashboard and alerts.
Security posture
What we touch — and what we never do
The answers your IT and security teams ask for before a single credential changes hands.
Read-only
Connectors have read access only. RegRisk never writes back to your ERP.
Least privilege
Credential-scoped service accounts, secrets held in a managed vault.
IP allow-listing
Egress restricted to known ranges; SSO and SCIM for platform access.
No prod footprint
Nothing is installed on your production application servers.
07 · In the field
Oracle Fusion access governance for a SOX audit
Global manufacturer · 12,000 employees · Fusion ERP + HCM. Drag the scrubber through two assessment cycles.
Cycle 0 · before RegRisk
Before · the challenge
Access review that was always six weeks stale
Reviews ran on spreadsheets exported quarterly — the data aged before anyone signed.
Auditors raised a significant deficiency on SoD monitoring two years running.
No way to test a proposed role change before it hit production.
100
critical conflicts, indexed to the first cycle
6wk
access review cycle time
open
SoD findings at the audit
modules · RCSA / SoD / Access Review / AI agents
End states are the reported figures: 78% fewer critical conflicts, 6wk → 2d review cycle, 0 SoD findings at the next audit. Intermediate positions are interpolated for the scrub.
Questions
What teams ask before the first sync
The answers your risk, audit and security leads want on the record. Every question here is linkable.
5 of 5 questions
No. Every agent proposes; a human disposes. Agents can read your data and draft outputs, but they hold write access only through an approval queue. Nothing enters the register, the control library or your ERP without a person accepting it.
Three things working together: outputs are grounded in your own records rather than a generic corpus, every suggestion carries a citation to its source, and a human approves before anything is committed. Claims the agent can't ground are flagged as unsupported instead of presented as fact.
No. Inference runs single-tenant and your data never trains a shared model. What the agents learn from your accept / reject decisions stays scoped to your tenant, tuning suggestions for your entities and taxonomy only.
Yes. Agents are licensed and enabled per module, and their write access is scoped per module and per role. You can run one agent, all six, or none — and require dual approval anywhere you need a second set of eyes.
An enterprise-grade frontier model, deployed single-tenant and version-pinned so its behaviour doesn't shift underneath you. The specific model is configurable, and every prompt and output is retained in the audit trail for inspection.
The free SoD assessment needs only read-only credentials. We connect, run a sync, and hand back your real conflicts — ranked, explained, and mapped to the roles that cause them.
Request the assessment
01Discovery workshop90 minutes with risk, audit and the ERP owner.
02Read-only connectionOne service account and a single sync job — nothing on production servers.
03Findings reviewYour own conflicts, ranked and explained, inside two weeks.
First conflicts inside two weeks · first SoD finding within 48 hours of the read-only connection.