Thank you all for the excellent insights. Let me synthesize what I’m hearing into a comprehensive approach:
SoD Policy Design:
The consensus is clear - one-size-fits-all SoD is counterproductive. A risk-based approach balances control and efficiency. Here’s a framework that emerged from this discussion:
Tier 1 (High Risk): Safety-critical BOMs, high-value assemblies (>$100K), BOMs for regulated products. Require strict maker-checker separation with dual approval from different departments. No exceptions, full audit trail mandatory.
Tier 2 (Medium Risk): Standard production BOMs, moderate value assemblies. Single approver from different department than creator. Emergency approval allowed with post-approval review within 48 hours.
Tier 3 (Low Risk): Prototype BOMs, spare parts, low-value items. Automated approval after 24-hour review period if no flags raised. Same-department approval permitted with audit logging.
The classification should be automated based on material type, BOM usage, estimated value, and regulatory flags in the material master. This eliminates subjective decisions about which path to follow.
Workflow Automation:
Manual approval processes create bottlenecks. Implement intelligent workflow with these capabilities:
- SLA-based escalation (24 hours to primary approver, then auto-escalate to deputy)
- Batch approval interface for reviewing multiple similar low-risk changes
- Mobile approval capability so approvers aren’t tied to their desks
- Out-of-office handling with automatic deputy assignment from organizational management
- Emergency approval path requiring two concurrent approvals from management level
The workflow should be configurable by BOM tier without code changes. Use SAP Business Workflow with custom approval steps based on BOM classification.
Audit Logging:
Comprehensive logging serves as a compensating control that allows more flexible approval processes. Log to custom table ZBOM_AUDIT_LOG:
- All BOM changes (create, modify, delete) with before/after values
- Approval actions (approved, rejected, escalated) with timestamps
- Emergency approval usage with business justification
- Auto-approval events for low-risk changes
- SoD policy exceptions with approval chain
Implement continuous monitoring that flags patterns like:
- Same user creating and approving multiple BOMs through emergency process
- Abnormal volume of emergency approvals from specific users
- BOM changes outside normal business hours
- Approval SLA violations trending upward
These logs satisfy audit requirements while supporting a more flexible operational model. The key insight is that SoD isn’t just about preventing individual unauthorized actions - it’s about creating a system of checks and balances that includes preventive controls (separation), detective controls (logging), and corrective controls (reviews).
A mature SoD program uses all three layers rather than relying solely on rigid separation that creates operational friction. The goal is appropriate control, not maximum control. Risk-based tiering, intelligent workflow automation, and comprehensive audit logging together achieve that balance.