Governance, Risk, and Compliance

Enterprise Resource Planning (ERP) serves as a cornerstone in ensuring effective Governance, Risk, and Compliance (GRC) within organizations. By integrating GRC modules, ERP systems provide a centralized platform to manage and monitor governance practices, identify and mitigate risks, and ensure compliance with regulatory requirements. This  approach enhances transparency and accountability across various business processes. ERP’s real-time reporting and analytics capabilities enable organizations to proactively identify potential risks and address compliance issues promptly. The integration of GRC within ERP streamlines workflows, promoting a culture of risk-aware decision-making. This synergy empowers organizations to navigate complex regulatory landscapes, mitigate risks efficiently, and uphold the highest standards of governance, ensuring a resilient and compliant operational environment.

NTT DATA and Pathlock Bring Always-On Cyber Defense to SAP Workflows
NTT DATA Business Solutions and Pathlock have joined forces to deliver always-on SAP cybersecurity — combining a managed SOC with AI-native application controls to protect finance, procurement, and supply chain workflows against unauthorized access, fraud, and misconfiguration at global scale.
Finance automation and treasury management
Perplexity Tests the Real Finance AI Question: Can the Agent Show Its Work?
Perplexity has introduced a finance-specific AI agent designed to provide trusted data integration, robust audit trails, and prebuilt workflows for corporate finance teams, emphasizing the importance of traceability for meeting audit and reporting requirements.
Tax compliance and readiness
Does Your ERP Know What Tax Regime You’re In? A Compliance Readiness FAQ for Enterprise Finance Leaders
Tax compliance has evolved into a critical board-level consideration for ERP systems, emphasizing the need for real-time reporting, continuous transaction controls, and adaptable architectures while leveraging AI to address compliance challenges across jurisdictions.
The SAP Migration Decision in 2026: Three Companies, Three Answers, One Urgent Security Context
In 2026, three distinct approaches to SAP migration are highlighted by Lwart Environmental Solutions, which opts to extend its current system for operational stability; Victrola, which successfully executes a greenfield migration to SAP Cloud ERP with significant reporting efficiencies; and Reveal USA, which emphasizes proving value before transformation by guaranteeing an 8x return on investment, reflecting a market grappling with simultaneous technical, operational, and security challenges.
Enterprise IT monitoring environment with multiple screens displaying system data, representing SAP security patching and authorization risk management.
SAP June Security Patch Day Puts ERP Trust Controls Under Pressure
SAP's June 2026 Security Patch Day highlighted significant ERP security risks, delivering 15 new Security Notes with a focus on foundational trust layers like SAML authentication and RFC communication, emphasizing the need for organizations to prioritize the remediation of vulnerabilities that affect authentication, access control, and supply chain risks in their SAP environments.
Security analyst monitoring code and identity access controls across multiple screens following accelerated AI-driven breach activity
SAP June Patch Day Brings Four Critical Fixes Across NetWeaver, ABAP, Commerce Cloud
SAP's June 2026 Security Patch Day issued four critical fixes for vulnerabilities affecting SAP NetWeaver, ABAP, Java, Commerce Cloud, and Data Hub, prompting priority patch application to safeguard systems, as outlined in 15 new security notes highlighting risks in authentication and memory management.
Lwart Extends SAP ECC 6 as Factory Expansion Raises ERP Migration Risk
Lwart Environmental Solutions has opted to maintain its SAP ECC 6 system amid a significant factory expansion, prioritizing stability and operational continuity over immediate ERP modernization.
SAP’s Autonomous Finance Push Turns CFO Attention to Governance
SAP’s autonomous finance push is moving CFO priorities toward governance, controls, and AI-ready financial processes. For SAP customers, the opportunity depends on how well automation, GRC, and finance transformation connect inside ERP operations.
SAP Sapphire Madrid
SAP Sapphire Madrid: Autonomous Enterprise Pitch Meets Europe’s AI Control Test
At SAP Sapphire Madrid, the company introduced the Autonomous Enterprise as the next evolution in ERP, focusing on AI-driven solutions tailored for European markets, emphasizing sovereignty and regulatory compliance in data handling and operational control.
ERP transformation
Transformation Capability Management: Why ERP Programs Drift Even with Good Change Management
ERP programs falter not from inadequate change management but from early weak structural decisions, with the need for 'Transformation Capability Management' (TCM) to ensure organizations build durable abilities rather than depend on external partners, as traditional change management alone cannot address underlying capability, capacity, and governance challenges.
AI is reshaping enterprise partnerships across ERP, supply chain, governance, and ecosystem collaboration
AI Is Changing the Rules of Enterprise Partnerships: Q&A with Blue Yonder’s VP Kelley Lear
In this ERP Today Q&A, Blue Yonder’s Kelley Lear explains how AI is changing the rules of enterprise partnerships. The discussion covers agentic AI, hyperscaler and ERP alliances, supply chain disruption, data readiness, governance, and what separates outcome-focused partnerships from those that stall.
Digital image of computer functions over person typing at a laptop.
How AI Is Forcing ERP Vendors to Rethink the Human Side of Transformation
Research indicates that 88% of chief human resource officers believe AI accelerates the readiness of early-career talent, placing pressure on ERP vendors to enhance their platforms for intuitive AI experiences, while also emphasizing the need for clear governance to mitigate risks.
SAP Security Has the Board’s Attention—Now What?
SAP security has gained visibility at the executive level but often fails to drive decisions due to a lack of effective translation of cyber risks into clear business impacts, as highlighted by Asha Vartak, emphasizing that awareness alone is insufficient for action in a landscape increasingly influenced by AI and regulatory pressures.
Rise with SAP Security Risk Is Increasingly Shaped by Timing, Data, Assurance
As organizations accelerate their migration to SAP S/4HANA Cloud Private Edition, security risks intensify, prompting a shift in focus towards proactive security measures, data-centric access control, and a structured assurance model to ensure effective protection and compliance in increasingly complex cloud environments.
Framework or Platform? How Sovos Is Turning Tax Compliance into an ERP Strategy Decision
The article discusses the urgent need for ERP programs to integrate tax compliance as a core architectural element rather than a secondary concern, emphasizing that organizations must choose between ERP-native frameworks or specialized third-party solutions to address rapidly evolving regulatory requirements, with the choice impacting operational flexibility, risk management, and overall compliance efficiency.
SAP logo displayed at company office, representing enterprise software security and monthly Patch Day updates.
SAP February Patch Day Puts ABAP and Platform Risk in Focus
SAP’s February 2026 Patch Day delivered 26 new notes and one update, with critical exposure centered in ABAP and core platform services. Vendors warn impact depends on how trust and integrations operate inside each landscape.
Bicycles parked in front of SAP office in Europe.
SAP’s EU AI Cloud Addresses Data Sovereignty as Regulations Tighten in Europe
SAP’s EU AI Cloud reflects how data sovereignty and regulation are reshaping where and how enterprises deploy AI in Europe.
The letters E, S, and G.
SAP Sustainability Control Tower: New Analytics Tab Enhances Reporting
SAP has enhanced the Sustainability Control Tower with an Analytics tab in the Analyze ESG Data app, allowing detailed, customizable views of ESG metrics, facilitating compliance with EU sustainability regulations, and enabling teams to manage reporting data efficiently.
Europe’s ERP Vendors Are Gaining Ground Alongside Oracle, Microsoft
European ERP vendors like SAP, Unit4, Odoo, AFAS, and Exact are emerging as viable alternatives to US giants by aligning with regional regulatory, data protection, and localization needs, particularly for organizations prioritizing compliance and sovereignty.
How the digital sovereignty agenda in the EU reshapes cybersecurity
The EU's push for digital sovereignty is transforming cybersecurity into a critical, integrated discipline, prompting businesses to adopt stringent regulations, lifecycle-embedded practices, and proactive risk management.
Year in Review: Testing, Transformation, and the Race to AI-Ready ERP in 2025
In 2025, the conversation around cloud migration shifted from why to how. According to SAPinsider’s 2025 research report on SAP S/4HANA deployment, for instance, 31% of the organizations who responded to the survey have transitioned to SAP S/4HANA, while another 27% are in implementation. Additionally, 54% of respondents said they plan to incorporate AI or...
SAP NS2 defense
The New SAP Defense
As organizations transition to SAP S/4HANA and hybrid-cloud architectures, the necessity for a layered Zero Trust security approach, supported by Unified Risk Management and consolidated monitoring solutions, becomes critical to address the expanded attack surface.
SAP, Oracle Lead the Charge as AI-Driven Performance Management Market Targets USD 6.33B by 2030
The employee performance management market is expected to grow from $3.52 billion in 2025 to $6.33 billion by 2030, driven by a shift towards continuous, analytics-enabled performance cycles embraced by major firms like Adobe and Microsoft, with AI-centric platforms at the core, as organizations increasingly link performance to skills-based talent strategies and digital transformation efforts.
SAP Sovereign Cloud
Five Risks SAP Leaders Can No Longer Ignore in 2026
As SAP vulnerabilities surge and attackers exploit weaknesses swiftly, organizations must prioritize automated security measures and cloud responsibility models while addressing legacy systems and integrating SAP into broader security operations to mitigate risks and safeguard critical business processes.
A lock is shown on top of a laptop keyboard | Onapsis
SAP Issues Three Critical Security Fixes in December Patch Day
On December 9, SAP released 14 security notes, including three critical patches for vulnerabilities in SAP Solution Manager, Apache Tomcat in SAP Commerce Cloud, and SAP jConnect, urging customers to prioritize updates based on severity to protect against potential exploits.
SAP SuccessFactors
Global HR Agent Delivers Real-Time Advisory for SAP SuccessFactors
Globalization Partners' G-P Gia is now available on SAP Store, providing real-time, compliant global HR guidance through an integration with SAP SuccessFactors and Joule, enhancing efficiency for multinational companies.
SAP Sovereign Cloud
SAP Is Building a Sovereign AI Stack for Europe
Regulatory trends in the EU are fostering a shift towards sovereign cloud and AI infrastructure, highlighted by companies like SAP, which has invested in local partnerships with firms like Mistral AI to enhance digital autonomy and develop industry-specific applications.
AI risk management
SAP Signavio AI Agent Mining Tackles Invisible Autonomy Risk
SAP users are increasingly incorporating AI agents into workflows, which introduce 'invisible autonomy' risks that necessitate oversight, prompting the launch of SAP Signavio's AI agent mining capability to enhance monitoring, efficiency, and performance assessment of these agents.
Citizen developers and governance in enterprise software today
The integration of AI into ERP systems heightens concerns over governance and security as citizen developers leverage low-code and no-code solutions, prompting enterprises to seek a balance between empowering these developers and maintaining compliance, illustrated by Mendix's approach to providing a structured platform that supports full software development lifecycle management.
laptop / how technology can help organizations get their houses in order
How technology can help organizations get their houses in order
The new EPR legislation will come into effect in 2025 and will require most large organizations to collect and report on plastic usage in their supply chain. Technology will be key in aiding companies to do so.