Skip to content

Case study Telecommunications

How a Telecommunications Company Replaced Manual Oracle EBS SoD Reviews with Continuous Access Governance

A telecommunications company preparing to list on a public exchange needed a defensible view of Oracle EBS segregation-of-duties risk. Periodic reviews were not producing it in time, access was assigned by hand at roughly $120,000 a year, and conflicts could sit unresolved until the next review cycle.

$120K → near zeroannual access-assignment cost
Zero findingson Oracle EBS ITGC at SOX review
6–8 monthsto a continuous SoD and access-risk lifecycle
IndustryTelecommunications
Primary ERPOracle E-Business Suite (EBS)
ApproachSoD analysis, preventive policy checks at provisioning, continuous conflict monitoring, remediation workflows, and auditable access-risk evidence

In about 6–8 months, the internal team used SafePaaS to replace periodic SoD reporting with a continuous access-risk lifecycle: identify existing risk, prevent new risk at the request, monitor Responsibilities as they change, remediate findings through a defined workflow, and sustain ownership after go-live.

The challenge

The company could produce a SoD report. What it could not produce was a repeatable process for preventing new conflicts, resolving open ones, and keeping evidence of those decisions — which is what an external auditor asks for ahead of a listing.

Four things drove the cost and the risk:

  • Manual access assignment. Requests were assigned by hand. The process cost approximately $120,000 a year, slowed delivery, and produced inconsistent decisions.
  • No consistent preventive check. New access did not reliably pass through policy and SoD checks before approval, so a conflicting Responsibility could be granted first and reviewed later.
  • Delayed visibility. Conflicts across Oracle EBS Responsibilities could remain unresolved until the next review cycle or audit brought them up.
  • No standard resolution path. When a conflict did surface, there was no agreed way to investigate it, document the decision, or close it.

In Oracle EBS this gap is easy to underestimate. Users receive access through Responsibilities, but the risk sits in the Functions, Concurrent Programs and organizational scope underneath them. Effective Oracle EBS segregation of duties and sensitive-access governance resolves what is actually beneath each Responsibility, then connects the conflicts it finds to prevention, mitigation and remediation.

A five-step SoD and access-risk lifecycle

The company’s internal team used SafePaaS to put a continuous process around Oracle EBS. The work followed five steps.

1. Identify existing SoD risk

The team defined SoD rules and policy requirements, then used them to identify conflicts and control gaps across Oracle EBS Responsibilities. That baseline showed which conflicts needed action before the listing, rather than waiting for an auditor to find them.

2. Prevent new conflicts

Manual access assignment was replaced with automated, policy-driven provisioning. Each request passed through defined policy and SoD checks before approval, so conflicting or inappropriate access was stopped at the request instead of being discovered later.

That single change cut the annual access-assignment cost from approximately $120,000 to near zero, and shortened the time it took to grant access.

3. Monitor Responsibilities as they change

Rules-based monitoring gave the team ongoing visibility into SoD risk across Oracle EBS Responsibilities. Conflicts were identified as assignments changed, not only during periodic reviews — and the same monitoring produced a consistent record of control activity through the certification period.

4. Remediate through a defined workflow

When monitoring found a conflict or policy issue, the finding went through a structured workflow. The team had one method for investigating the issue, documenting the decision, and closing the risk.

Preventive checks reduced the number of new conflicts. Detection and remediation reduced how long existing conflicts stayed open. Together they produced a significant reduction in SoD violations.

5. Sustain ownership after go-live

The company documented a repeatable operating model for Oracle EBS SoD and access governance. Continuous monitoring and evidence generation let the internal team keep the process running after the first certification effort ended.

The organization completed its SOX review with zero findings related to Oracle EBS IT general controls.

From periodic SoD reviews to continuous governance

Area Before After
Access assignment Manual process costing approximately $120,000 a year Automated, policy-driven provisioning at near-zero assignment cost
Preventive controls Access could be granted before policy and SoD were checked Policy and SoD checks applied at the request, before approval
SoD visibility Conflicts surfaced at the next review cycle or audit Rules-based monitoring as Responsibility assignments change
Remediation No standard way to investigate, document or close a conflict Structured workflow from finding to documented closure
Audit evidence Assembled when someone asked for it Produced by the operating process itself
SOX outcome Uncertain control position ahead of listing Zero findings related to Oracle EBS IT general controls

What this changed

The company stopped treating SoD reporting as the finish line and built a lifecycle for identifying, preventing, monitoring, remediating and sustaining access risk in Oracle EBS.

Automated provisioning removed a costly manual step and evaluated each request against policy before approval. Continuous monitoring and defined remediation workflows gave the team a consistent way to find and close conflicts. The evidence needed to show those controls were operating came out of the same process rather than being reconstructed for the auditor.

The result was a repeatable SoD and access-governance model: lower assignment cost, fewer open violations, and a control record that held up under SOX review.

What this means if you run Oracle EBS

If your team still assigns Responsibilities by hand, finds SoD conflicts in a periodic extract, and builds access evidence when audit season starts, you are where this company started. A governance-ready process can answer five questions about any access assignment:

  1. What access does this Responsibility actually grant, beneath the Responsibility name?
  2. Does granting it create an SoD conflict or hand over a privileged capability?
  3. Was that evaluated before approval, or discovered afterwards?
  4. Who investigated the conflict, and what did they decide?
  5. Can you prove the decision and its follow-through without rebuilding the trail?

Use these Oracle EBS SoD audit-readiness criteria to compare this operating model with the controls and evidence available in your own environment.

Oracle EBS SoD and privileged access FAQ

Why is a Responsibility-level SoD report not enough?

A Responsibility is a container. The access that creates a conflict lives in the Functions, Concurrent Programs and organizational scope underneath it, so a report written at Responsibility level can miss conflicts that exist and flag conflicts that do not. Resolving what sits beneath the Responsibility is what makes the analysis defensible.

How did this company remove $120,000 a year of assignment cost?

It replaced manual, coordinated access assignment with automated provisioning that evaluated each request against policy and SoD rules before approval. The cost was in the manual coordination, and automating the decision removed it.

What did zero SOX findings on Oracle EBS ITGCs require?

More than a report at year end. It required preventive checks at the point of request, continuous monitoring of SoD risk as assignments changed, a defined remediation workflow, and evidence generated by the control process rather than assembled for the audit.

How long did the implementation take?

Approximately 6–8 months, with the internal team retaining ownership of the operating model after the first certification effort.

Next step

Complete the Oracle EBS Segregation of Duties & Privileged Access Checklist to identify whether your current process has similar gaps in privileged-access oversight, conflict analysis, remediation or evidence.

To see your own Oracle EBS SoD conflicts and privileged Responsibilities, request an Oracle EBS SoD and access risk assessment.

See it on your ERP

A 30-minute walkthrough against the systems you actually run.

See how this model applies to the systems sitting inside your own estate.

What this story shows

  • Annual access-assignment costs fell from about $120,000 to near zero
  • SoD violations across Oracle EBS Responsibilities dropped significantly
  • SOX review completed with zero findings related to Oracle EBS IT general controls
  • Manual, periodic SoD reviews were replaced by a continuous access-risk lifecycle