CheckAud
by IBS Schreiber GmbH · Access Controls & SoD
SAP authorization and SoD audit software analyzing exported system data for compliance risk.
Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.
- Works with
SAP- Company size
- Mid-market, Enterprise
- Pricing
- Tiered: free assessment, fixed-fee proof of concept, quote-based license
- Founded
- 1979
- Headquarters
- Hamburg, Germany
Overview
CheckAud is an SAP authorization and compliance-audit tool developed by IBS Schreiber GmbH, a Hamburg, Germany-based SAP security specialist founded in 1979. It analyzes data exported from SAP ECC and S/4HANA systems to identify segregation-of-duties (SoD) conflicts, excessive permissions, and configuration/parameter risks, without requiring an add-on installed inside the production system.
The product organizes analysis into can-do checks (what a user is authorized to do), did-do checks (what a user actually did, drawn from log data), and parameter checks (system configuration risk), each scored for risk severity. Reports are built to align with IDW PS 880, the German standard for software-supported audits, and the tool includes reference rule sets addressing DSAG, GDPR and SOX-relevant controls. It supports multi-client and multi-system analysis for organizations auditing several SAP instances at once, including authorization clean-up ahead of SAP S/4HANA migrations.
CheckAud is positioned as a detective control that complements preventive SAP GRC access-control systems by monitoring what is actually configured and used in a live system, rather than only what is approved at role-creation time. IBS Schreiber also offers related SAP security consulting, the CASA (Certified Auditor for SAP Applications) training program developed with ISACA, and a companion product, Easy Content Solution (ECS).
Screenshots & demo
Demo video from the vendor's YouTube channel.
Features & capabilities
Authorization & SoD Analysis
Automated analysis of SAP roles and authorizations for conflicts and excess access.
- Segregation-of-duties (SoD) conflict detection with risk scoring
- Can-Do analysis of excessive or unused permissions
- Did-Do analysis of actual user activity from system logs
- Field-level authorization checks across SAP modules
- Critical parameter and system-configuration checks
- Support for custom and IBS Schreiber-supplied risk rule sets
Multi-System & Migration Support
Cross-landscape analysis and migration readiness.
- Multi-client and multi-system (cross-landscape) analysis
- SAP S/4HANA migration authorization validation
- Role-concept clean-up ahead of migration
- International, group-wide rollout support
Compliance & Reporting
Audit-ready reporting aligned to recognized standards.
- Audit-ready reports generated automatically
- IDW PS 880-aligned audit methodology
- Reference rule sets covering DSAG, GDPR and SOX-relevant controls
- Management-level risk dashboards and prioritized findings
- Continuous, recurring compliance-monitoring option
Deployment & Integration
Lightweight deployment model built around exported system data.
- Plug-and-play deployment using exported SAP data
- No modification to the production SAP system
- Interfaces for data export and system-to-system comparison
- Complements SAP GRC Access Control and IDM processes as a detective layer
Common use cases
- Preparing for external or internal SAP authorization audits with IDW PS 880-aligned reporting
- Detecting segregation-of-duties conflicts across SAP ECC or S/4HANA roles
- Cleaning up excessive or unused permissions before an S/4HANA migration
- Running continuous, detective monitoring of SAP authorizations alongside a preventive GRC tool
- Comparing authorizations and configuration across multiple SAP clients or systems in a group structure
- Producing audit-ready evidence for SOX or GDPR-relevant access controls
- Replacing manual, spreadsheet-based SAP authorization reviews
Strengths & considerations
Strengths
- Analyzes exported SAP data rather than requiring an add-on installed inside the production system
- Purpose-built for IDW PS 880-compliant audit reporting, developed by an SAP security specialist operating since 1979
- Positioned as a detective control that complements, rather than replaces, preventive SAP GRC Access Control systems
- Maintained risk rule set library addressing DSAG, GDPR and SOX-relevant frameworks
ERP integrations
Analyzes data exported from SAP ECC and S/4HANA systems; no installation inside the production system required
Pricing
Free one-time Security Check assessment; 30-day Proof of Concept license is a fixed EUR 1,490 fee including a workshop; ongoing Company License for continuous, multi-system compliance is quote-based. Get an independent shortlist with pricing guidance below.
Technical & security
- Compliance
- IDW PS 880
- Languages
- German, English
About the vendor
- Founded
- 1979
- Headquarters
- Hamburg, Germany
- Ownership
- Private (GmbH)
- Notable customers
- Caterpillar, JOST-Werke
Alternatives to CheckAud in Access Controls & SoD
CheckAud — frequently asked questions
How is CheckAud different from an SAP GRC system?
CheckAud complements preventive SAP GRC systems, which check authorizations at role-creation time, with detective analysis of the live system as actually configured. It surfaces risks that a preventive, role-design-only check would not catch.
Does CheckAud replace manual SAP authorization reviews?
IBS Schreiber positions CheckAud as an automation layer for manual, spreadsheet-based authorization reviews, citing time savings of up to 80 percent compared with manual analysis, plus objective, repeatable risk scoring.
Does CheckAud support SAP S/4HANA migration projects?
Yes. CheckAud is used to clean up critical authorizations and avoid carrying forward segregation-of-duties conflicts as organizations migrate from SAP ECC to S/4HANA.
Can CheckAud analyze multiple SAP systems or clients at once?
Yes. CheckAud is built for multi-client and multi-system (cross-landscape) scenarios, supporting organizations that need to compare authorizations and risk across several SAP instances.
What audit standard does CheckAud's reporting follow?
CheckAud generates reports aligned to IDW PS 880, the German standard for software-supported audits, and includes reference rule sets addressing DSAG, GDPR and SOX-relevant controls.
Evaluating Access Controls & SoD?
Tell us your ERP and requirements and we'll send an independent shortlist — including CheckAud and the best-fit alternatives — with honest pros and cons.