CheckAud
by IBS Schreiber GmbH · Access Controls & SoD
SAP authorization and SoD audit software analyzing exported system data for compliance risk.
Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.
- Works with
SAP- Company size
- Mid-market, Enterprise
- Pricing
- Tiered: free assessment, fixed-fee proof of concept, quote-based license
- Founded
- 1979
- Headquarters
- Hamburg, Germany
Overview
CheckAud is an SAP authorization and compliance-audit tool developed by IBS Schreiber GmbH, a Hamburg, Germany-based SAP security specialist founded in 1979. It analyzes data exported from SAP ECC and S/4HANA systems to identify segregation-of-duties (SoD) conflicts, excessive permissions, and configuration/parameter risks, without requiring an add-on installed inside the production system.
The product organizes analysis into can-do checks (what a user is authorized to do), did-do checks (what a user actually did, drawn from log data), and parameter checks (system configuration risk), each scored for risk severity. Reports are built to align with IDW PS 880, the German standard for software-supported audits, and the tool includes reference rule sets addressing DSAG, GDPR and SOX-relevant controls. It supports multi-client and multi-system analysis for organizations auditing several SAP instances at once, including authorization clean-up ahead of SAP S/4HANA migrations.
CheckAud is positioned as a detective control that complements preventive SAP GRC access-control systems by monitoring what is actually configured and used in a live system, rather than only what is approved at role-creation time. IBS Schreiber also offers related SAP security consulting, the CASA (Certified Auditor for SAP Applications) training program developed with ISACA, and a companion product, Easy Content Solution (ECS).
Screenshots & demo
Demo video from the vendor's YouTube channel.
Modules & capabilities
CheckAud covers 19 of 51 capabilities we track in this category (+1 partial)
37%- Segregation-of-duties conflict detectionSoD conflict detection with risk scoring is the core productCore strength
- Critical / sensitive access detectionCritical parameter and system-configuration checks; field-level checks across modulesCore strength
- Risk scoring and prioritizationRisk-scored SoD findingsSupported
- Prebuilt risk rule libraryReference rule sets covering DSAG, GDPR and SOX-relevant controls, plus IBS Schreiber-supplied setsSupported
- Custom rule authoringSupport for custom risk rule setsSupported
- Cross-system risk analysisMulti-client and multi-system (cross-landscape) analysisCore strength
- Organizational-scope violation detectionNot evidenced
- Usage-based risk prioritization"Did-Do" analysis of actual user activity from system logs, distinct from "Can-Do" excess-permission analysisCore strength
“Not evidenced” means our research found no public documentation of this capability — the vendor may still offer it. Confirm on a demo.
Common use cases
- Preparing for external or internal SAP authorization audits with IDW PS 880-aligned reporting
- Detecting segregation-of-duties conflicts across SAP ECC or S/4HANA roles
- Cleaning up excessive or unused permissions before an S/4HANA migration
- Running continuous, detective monitoring of SAP authorizations alongside a preventive GRC tool
- Comparing authorizations and configuration across multiple SAP clients or systems in a group structure
- Producing audit-ready evidence for SOX or GDPR-relevant access controls
- Replacing manual, spreadsheet-based SAP authorization reviews
Strengths & considerations
Strengths
- Analyzes exported SAP data rather than requiring an add-on installed inside the production system
- Purpose-built for IDW PS 880-compliant audit reporting, developed by an SAP security specialist operating since 1979
- Positioned as a detective control that complements, rather than replaces, preventive SAP GRC Access Control systems
- Maintained risk rule set library addressing DSAG, GDPR and SOX-relevant frameworks
Used CheckAud with your ERP? Rate it in 30 seconds — it helps every buyer after you.
Rate itERP integrations
Analyzes data exported from SAP ECC and S/4HANA; plug-and-play, no installation inside the production SAP system. No SAP Store listing found.
Connector details independently verified against vendor marketplaces and documentation; last checked 2026-08-20.
Pricing
Full CheckAud pricing breakdown — cost at 25/100/500 seats, competitor rates & FAQs
Free one-time Security Check assessment; 30-day Proof of Concept license is a fixed EUR 1,490 fee including a workshop; ongoing Company License for continuous, multi-system compliance is quote-based. Get an independent shortlist with pricing guidance below.
What does CheckAud cost?
CheckAud prices by quote, like most of this category. Here is what actually drives your number — and what to ask before you get one.
4 of the 9 vendors we track in this category publish no list price at all.
Technical & security
- Compliance
- IDW PS 880
- Languages
- German, English
About the vendor
- Founded
- 1979
- Headquarters
- Hamburg, Germany
- Ownership
- Private (GmbH)
- Notable customers
- Caterpillar, JOST-Werke
Alternatives to CheckAud in Access Controls & SoD
CheckAud — frequently asked questions
How is CheckAud different from an SAP GRC system?
CheckAud complements preventive SAP GRC systems, which check authorizations at role-creation time, with detective analysis of the live system as actually configured. It surfaces risks that a preventive, role-design-only check would not catch.
Does CheckAud replace manual SAP authorization reviews?
IBS Schreiber positions CheckAud as an automation layer for manual, spreadsheet-based authorization reviews, citing time savings of up to 80 percent compared with manual analysis, plus objective, repeatable risk scoring.
Does CheckAud support SAP S/4HANA migration projects?
Yes. CheckAud is used to clean up critical authorizations and avoid carrying forward segregation-of-duties conflicts as organizations migrate from SAP ECC to S/4HANA.
Can CheckAud analyze multiple SAP systems or clients at once?
Yes. CheckAud is built for multi-client and multi-system (cross-landscape) scenarios, supporting organizations that need to compare authorizations and risk across several SAP instances.
What audit standard does CheckAud's reporting follow?
CheckAud generates reports aligned to IDW PS 880, the German standard for software-supported audits, and includes reference rule sets addressing DSAG, GDPR and SOX-relevant controls.
Compare CheckAud head-to-head
The Access Controls & SoD Buyer's Guide
Before you commit to CheckAud, see how it sits against the 9 access controls & SoD systems we track — on capability, ERP integration depth and what each one actually charges for.
Access Controls & SoD Buyer's Guide
9 systems compared · 2026
ERP Research
- CheckAud compared side-by-side with 8 alternatives
- ERP integration checklist — what to verify before you shortlist
- The pricing questions that change the quote
- A CheckAud evaluation brief, included with the guide
Access Controls & SoD Buyer's Guide
Get a quote for CheckAud
CheckAud publishes a list price, but the number you pay depends on volume, modules and integration scope. Tell us your setup and we'll come back with a realistic figure and the alternatives worth quoting against it.