Pathlock and KPMG LLP announced on August 3 an alliance aimed at helping large enterprises govern identity security and access risk across complex, multi-application environments as they modernize core business systems. Pathlock said the relationship will focus on enterprises running billions of dollars of transactions through ERP and other business-critical systems.
The alliance brings together Pathlock’s identity and access governance platform with KPMG’s cybersecurity, compliance, risk, and transformation advisory capabilities. The announcement lands at a time when ERP modernization is expanding the access-governance challenge. Cloud migrations, application consolidation, AI agents, automation, and business-process redesign can all change who or what can access sensitive workflows, approve transactions, elevate privileges, and create audit exposure.
Pathlock described its platform as an AI-native, multi-tenant SaaS offering that unifies identity governance, access risk analysis, elevated access management, application controls, and continuous monitoring. The platform is designed to combine fine-grained access governance with real-time transaction-level analytics, helping organizations detect risky behavior and maintain auditability across the applications that run the business.
For ERP customers, the important point is the transaction layer. Access governance in enterprise systems is not only about whether a user can log in. It is about whether that user, service account, automated workflow, or AI-enabled process can initiate, approve, change, or conceal activity inside finance, HR, procurement, supply chain, and other controlled processes.
Identity Controls Move into Transformation
The alliance is structured around joint execution. Pathlock said that when KPMG works with clients on ERP risk transformation or technology modernization, Pathlock can become part of the solution for identity security and access risk management.
KPMG brings experience across regulatory and compliance domains including SOX, HIPAA, PCI DSS, and GDPR. That gives the alliance a clear audit-readiness angle: organizations need access governance that can support transformation without forcing control evidence, risk analysis, and compliance monitoring into manual after-the-fact work.
Mick McGarry, Principal, Cybersecurity Services at KPMG LLP, said the firm is focused on helping clients use AI while maintaining cybersecurity resilience. He said combining identity governance with behavioral insights and cybersecurity frameworks can help organizations manage access and transaction risk.
Damon Tompkins, CEO of Pathlock, said the alliance brings together KPMG’s compliance, risk, and transformation expertise with Pathlock’s technology to help organizations modernize identity access and governance programs with cost savings and confidence.
The announcement also reflects a broader shift in ERP security. As businesses move from static roles and periodic access reviews toward continuous controls and AI-supported monitoring, governance needs to account for both human and non-human identities. Pathlock said its platform is used by Global 2000 organizations running complex SAP, Oracle, and Workday environments, and is built to govern every identity and every transaction at scale.
Get Our Free Weekly Newsletter
AI Governance Starts with ERP Access
The Pathlock-KPMG alliance shows why AI governance is becoming inseparable from ERP access governance. As organizations introduce AI agents and automated processes into core systems, the question is not only what a model can generate. It is what connected agents, users, and workflows are allowed to do inside controlled business processes.
That is especially relevant for finance and audit teams. If AI-enabled tools are used to support close, procurement, payroll, compliance, invoice processing, or controls testing, companies need visibility into permissions, transactions, exceptions, elevated access, and control violations. A governance model that stops at the application boundary will miss much of the operational risk.
The practical value of the alliance will depend on execution. Enterprises will need to see how Pathlock’s controls and analytics fit into KPMG-led transformation programs, how quickly access-risk insights can be operationalized, and whether the combination reduces audit burden without creating another governance silo.
Sponsor Industry‑Grade Research
What This Means for ERP Insiders
Access governance belongs inside ERP transformation planning. Modernization programs often focus first on platform selection, data migration, integrations, and process redesign, but access risk can undermine all of those workstreams if it is treated as a late-stage control exercise. ERP program leaders, CISOs, and audit teams need to build identity governance into the transformation roadmap from the start.
AI agents raise the stakes for transaction-level controls. As non-human identities begin acting across business systems, organizations need to know which actions they can take, which controls apply, and how exceptions are detected. Security and GRC leaders should expect ERP access policies to become more dynamic, behavioral, and evidence-driven.
Audit readiness is becoming a technology architecture issue. Manual reviews and periodic control checks cannot keep pace with continuous business change, cloud migrations, and agentic automation. For systems integrators, advisory firms, and ERP vendors, the opportunity is to connect identity, controls, monitoring, and audit evidence directly into the application environment rather than bolt them on after go-live.




