{"id":62040,"date":"2026-05-12T14:10:59","date_gmt":"2026-05-12T12:10:59","guid":{"rendered":"https:\/\/xiting.com\/?post_type=news&#038;p=62040"},"modified":"2026-05-12T14:11:47","modified_gmt":"2026-05-12T12:11:47","slug":"sap-compliance-efficient-risk-minimization-with-xcw-craf","status":"publish","type":"news","link":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/","title":{"rendered":"SAP &#038; Compliance: Efficient Risk Minimization with XCW &#038; CRAF"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"62040\" class=\"elementor elementor-62040 elementor-60667\" data-elementor-post-type=\"news\">\n\t\t\t\t<div class=\"elementor-element elementor-element-79b93fa e-flex e-con-boxed e-con e-parent\" data-id=\"79b93fa\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3e43790 elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"3e43790\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">SAP Access Control Upgrade and Migration Service<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-e64d578 e-con-full e-flex e-con e-child\" data-id=\"e64d578\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-930689b elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"930689b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-calendar-alt\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">24 July 2020<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6211574 elementor-widget__width-auto elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"6211574\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-equals\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">News<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-26e5c69 elementor-widget__width-auto elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"26e5c69\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-user\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Hazhan Salih<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d5c871d elementor-widget elementor-widget-image\" data-id=\"d5c871d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"9888\" height=\"3461\" src=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy.png\" class=\"attachment-full size-full wp-image-41575\" alt=\"\" srcset=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy.png 9888w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy-300x105.png 300w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy-1024x358.png 1024w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy-768x269.png 768w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy-1536x538.png 1536w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy-2048x717.png 2048w\" sizes=\"(max-width: 9888px) 100vw, 9888px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e128f85 elementor-widget elementor-widget-text-editor\" data-id=\"e128f85\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2 id=\"h-basic-understanding-of-sap-authorizations\" class=\"wp-block-heading\">Basic understanding of SAP authorizations<\/h2>\n<p>Understanding SAP authorizations, especially with regard to compliance, is crucial for ensuring corporate security and compliance with legal and regulatory requirements. SAP systems offer an extensive and complex authorization structure that enables detailed control over which data and processes individual users are allowed to access. This is particularly important in terms of compliance, as inappropriate access rights can lead to security breaches and violations of legal regulations.<\/p>\n<h2 class=\"wp-block-heading\">In-depth consideration of the SAP authorization structure<\/h2>\n<p>The SAP authorization structure is designed to enable finely graded access rights. This structure includes:<\/p>\n<ul>\n<li><strong>Roles and profiles<\/strong>: Roles define which transactions and functions are accessible to a user. Profiles are technical implementations of these roles that can be assigned directly to a user account.<\/li>\n<li><strong>Authorization objects<\/strong>: These specify the exact activities that may be carried out within a transaction. Authorization objects contain fields that can take on certain values in order to further refine access.<\/li>\n<\/ul>\n<p><\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" class=\"alignnone wp-image-41579\" src=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-1-english-1024x189.png\" alt=\"Icon graphic: Workflow for SAP user requests and risk checks\" width=\"1024\" height=\"189\" srcset=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-1-english-1024x189.png 1024w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-1-english-300x55.png 300w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-1-english-768x141.png 768w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-1-english.png 1086w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<p><\/p>\n<h2 class=\"wp-block-heading\">Compliance requirements in SAP authorizations<\/h2>\n<p>Compliance in SAP authorizations means that access rights are configured in such a way that they comply with legal regulations and internal guidelines. This includes :<\/p>\n<ul>\n<li><strong>Data protection and security<\/strong>: Compliance with laws such as the GDPR, which regulates the protection of personal data.<\/li>\n<li><strong>Internal control systems (ICS)<\/strong>: Establishment of control mechanisms to ensure that financial reporting is correct and fraud is prevented.<\/li>\n<li><strong>Audit trails<\/strong>: Ensure that all system activities are logged so that they can be traced and checked if necessary.<\/li>\n<\/ul>\n<p><\/p>\n<h2 class=\"wp-block-heading\">Risks of non-compliance<\/h2>\n<p>Failure to comply with SAP authorizations can result in a number of serious risks that can cause both immediate financial losses and long-term damage to the company&#8217;s image and operational stability.<\/p>\n<h3 class=\"wp-block-heading\">Operative disorders<\/h3>\n<p>Incorrectly configured permissions lead to delays and inefficiencies. Excessive access can lead to data leaks and internal fraud, requiring costly corrections and security investigations.<\/p>\n<h3 class=\"wp-block-heading\">Data theft and loss<\/h3>\n<p>Inadequately secured authorizations enable data theft and loss, which leads to financial losses and damage to the competitive position.<\/p>\n<h3 class=\"wp-block-heading\">Increased audit and monitoring costs<\/h3>\n<p>Compliance violations lead to more frequent and more thorough audits, which increases internal costs for compliance management and monitoring.<\/p>\n<h2 class=\"wp-block-heading\">Challenges in compliance management<\/h2>\n<p>The management of compliance, especially in the area of SAP authorizations, is faced with a variety of challenges.<\/p>\n<h3 class=\"wp-block-heading\">Dynamic changes in business processes<\/h3>\n<p>In a fast-moving business world, authorization settings must be continuously adapted to keep pace with changes in business processes. An agile compliance management system is required to respond quickly and efficiently to these changes.<\/p>\n<h3 class=\"wp-block-heading\">Segregation of Duties (SoD)<\/h3>\n<p>Segregation of duties and responsibilities (SoD) minimizes fraud and errors by ensuring that no individual can perform a complete transaction on their own. This requires careful planning and monitoring to distribute roles and authorizations in a way that minimizes risk.<\/p>\n<h3 class=\"wp-block-heading\">Compliance monitoring and auditing<\/h3>\n<p>SAP systems must be regularly checked for compliance requirements. These audits are time-consuming, complex and require specialized knowledge to ensure the correct assignment and use of all authorizations.<\/p>\n<h2 class=\"wp-block-heading\">XCW &amp; CRAF as a solution for compliance<\/h2>\n<p><\/p>\n<h3 class=\"wp-block-heading\">XCW (Xiting Central Workflows)<\/h3>\n<p>XCW is a user-friendly and modern software solution that is based on standardized SAP workflows and specifically targets the challenges of compliance and authorization management.<\/p>\n<p><strong>Integration with XAMS and CRAF<\/strong><\/p>\n<p>XCW can be licensed together with the extended version of the Xiting Authorizations Management Suite (XAMS). This integration enables seamless collaboration between XCW and XAMS, providing a comprehensive solution for workflow and access management.<\/p>\n<h3 class=\"wp-block-heading\">The Critical Authorization Framework (CRAF)<\/h3>\n<p>CRAF is an integral part of the Xiting Authorizations Management Suite (XAMS) and is used to identify critical authorizations and ensure compliance with Segregation of Duties (SoD) policies.<\/p>\n<p><strong>How CRAF works<\/strong><\/p>\n<p>CRAF works in combination with XCW by performing comprehensive checks when a role is requested. When a new role is requested, XCW uses CRAF to automatically analyze the risk combinations of the authorization objects to be assigned and checks the existing authorizations of the person concerned. Potential conflicts are identified during the analysis, in particular SoD conflicts. If a conflict is detected, XCW automatically starts another approval process.<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" class=\"alignnone wp-image-41581\" src=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-2-engl-1024x141.png\" alt=\"Screenshot: Another approval Process in the XCW after an SoD Conflict was detected\" width=\"1024\" height=\"141\" srcset=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-2-engl-1024x141.png 1024w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-2-engl-300x41.png 300w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-2-engl-768x106.png 768w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-2-engl-1536x212.png 1536w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-2-engl-2048x282.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<p><strong>Advantages of CRAF integration<\/strong><\/p>\n<ul>\n<li><strong>Automated identification of critical authorizations<\/strong><\/li>\n<li><strong>Efficient management of SoD conflicts<\/strong><\/li>\n<li><strong>Transparent compliance reports<\/strong><\/li>\n<li><strong>Integration with XCW<\/strong><\/li>\n<\/ul>\n<p><\/p>\n<h3 class=\"wp-block-heading\">XCW can do more than just compliance with CRAF<\/h3>\n<p>XCW (Xiting Central Workflows) offers much more than just integration and use in combination with CRAF to meet compliance requirements. It is a comprehensive IAM tool that provides a variety of functions to optimize user and authorization management in SAP ABAP systems. Here are some of the additional features and benefits of XCW:<\/p>\n<h3 class=\"wp-block-heading\">Self-service workflows<\/h3>\n<p>XCW relieves the helpdesk and administrators through self-service workflows such as password reset and user unlocking. These functions reduce the support workload and significantly improve the user experience.<\/p>\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-41583\" style=\"width: 533px; height: auto;\" src=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-3-engl.png\" alt=\"XCW Password reset self-service in SAP System\" width=\"774\" height=\"675\" srcset=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-3-engl.png 774w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-3-engl-300x262.png 300w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-3-engl-768x670.png 768w\" sizes=\"(max-width: 774px) 100vw, 774px\" \/><\/figure>\n<p><\/p>\n<h3 class=\"wp-block-heading\">User and role content<\/h3>\n<p>XCW enables the definition of user and role owners who are responsible for approving user creations and role assignments. This supports compliance with security guidelines and ensures that only authorized persons have access to certain data and functions.<\/p>\n<h3 class=\"wp-block-heading\">Flexible implementation options<\/h3>\n<p>XCW is a stand-alone product in the SAP ABAP landscape that requires no additional hardware and is available both via SAP GUI and the more modern Fiori user interface. This flexibility facilitates implementation and use, regardless of the existing IT infrastructure.<\/p>\n<h3 class=\"wp-block-heading\">Dashboards and reports<\/h3>\n<p>With XCW, users can easily view the status of user and role requests via dashboards, which supports transparency and facilitates audits. This feature provides a clear overview of all activities and approvals, which simplifies compliance monitoring and improves risk management.<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-41586\" src=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-4-engl-1024x551.png\" alt=\"Screenshot: Dashboard for monitoring critical authorizations in XCW\/CRAF\" width=\"1024\" height=\"551\" srcset=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-4-engl-1024x551.png 1024w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-4-engl-300x161.png 300w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-4-engl-768x413.png 768w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-4-engl-1536x826.png 1536w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/abb.-4-engl-2048x1101.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<p><\/p>\n<h3 class=\"wp-block-heading\">Conclusion<\/h3>\n<p>XCW offers companies an efficient and effective solution for managing SAP authorizations and meeting compliance requirements. The combination of automation, self-service workflows and seamless integration with XAMS and CRAF makes XCW a powerful tool that assists organizations in achieving their security and compliance goals.<\/p>\n<h2 class=\"wp-block-heading\">FAQs<\/h2>\n<p><\/p>\n<div class=\"schema-faq\">\n<div id=\"faq-question-1720528540206\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What is XCW?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">A software solution for automating user provisioning and managing the user lifecycle in SAP ABAP systems.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528552416\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What is CRAF?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">A framework for identifying and managing critical authorizations and SoD conflicts.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528567205\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How does CRAF integrate with XCW?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">CRAF automatically checks risk combinations for role requests and starts additional approval processes in the event of conflicts.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528578973\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What are the advantages of integrating XCW and XAMS?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Seamless collaboration and comprehensive workflow and access management.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528586667\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What are SoD conflicts?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Conflicts where one individual can perform too many critical functions.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528599486\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>Why is CRAF important?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">It helps to minimize security risks and meet compliance requirements.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528621131\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How does the automatic authorization check work?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">CRAF analyzes the risk combinations of the authorizations and checks existing authorizations during role requests.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528632665\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>Who benefits from CRAF?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Companies of all sizes, especially in highly regulated industries.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528669835\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How quickly can XCW be implemented?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Usually within one to three days.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528678303\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What self-service workflows does XCW offer?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Password reset and user unlocking.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528686486\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What are critical authorizations?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Authorizations that are particularly sensitive and require special monitoring.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528700603\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What reports does CRAF create?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Detailed reports and dashboards on the compliance situation.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528719268\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>Can CRAF be customized?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Yes, companies can create a customized risk ruleset.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528734058\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How does CRAF support compliance?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Through automatic identification of SoD conflicts and critical authorizations.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528791389\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How are conflicts resolved at CRAF?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Through additional approval processes when conflicts are detected.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528803907\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>What is the Xiting Authorizations Management Suite (XAMS)?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">A suite for managing and analyzing SAP authorizations.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528811961\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>Can XCW be used independently?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Yes, it can be used independently or together with XAMS.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528817865\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How does CRAF help with compliance with legal requirements?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">By identifying and managing critical authorizations and SoD conflicts.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528834823\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>Which companies should use CRAF?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">Companies that use SAP systems and have to meet strict compliance requirements.<\/p>\n<\/div>\n<p><\/p>\n<div id=\"faq-question-1720528843229\" class=\"schema-faq-section\"><strong class=\"schema-faq-question\"><strong>How does CRAF assist in complying with legal requirements?<\/strong><\/strong><\/p>\n<p class=\"schema-faq-answer\">By identifying and managing critical authorizations and SoD conflicts.<\/p>\n<\/div>\n<p><\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"author":77,"featured_media":41575,"template":"elementor_header_footer","class_list":["post-62040","news","type-news","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.5 (Yoast SEO v27.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAP &amp; Compliance: Efficient Risk Minimization with XCW &amp; CRAF - Xiting<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAP &#038; Compliance: Efficient Risk Minimization with XCW &#038; CRAF\" \/>\n<meta property=\"og:description\" content=\"SAP Access Control Upgrade and Migration Service 24 July 2020 News Hazhan Salih Basic understanding of SAP authorizations Understanding SAP authorizations, especially with regard to compliance, is crucial for ensuring corporate security and compliance with legal and regulatory requirements. SAP systems offer an extensive and complex authorization structure that enables detailed control over which data [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/\" \/>\n<meta property=\"og:site_name\" content=\"Xiting\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/XitingAG\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-12T12:11:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy-1024x358.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"358\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/\",\"url\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/\",\"name\":\"SAP & Compliance: Efficient Risk Minimization with XCW & CRAF - Xiting\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/shutterstock_2381539687-copy.png\",\"datePublished\":\"2026-05-12T12:10:59+00:00\",\"dateModified\":\"2026-05-12T12:11:47+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/#primaryimage\",\"url\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/shutterstock_2381539687-copy.png\",\"contentUrl\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/shutterstock_2381539687-copy.png\",\"width\":9888,\"height\":3461},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/sap-compliance-efficient-risk-minimization-with-xcw-craf\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/xiting.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"News\",\"item\":\"https:\\\/\\\/xiting.com\\\/en\\\/news\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"SAP &#038; Compliance: Efficient Risk Minimization with XCW &#038; CRAF\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/xiting.com\\\/en\\\/\",\"name\":\"Xiting\",\"description\":\"Your Expert for SAP Security\",\"publisher\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/xiting.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/#organization\",\"name\":\"Xiting\",\"url\":\"https:\\\/\\\/xiting.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/xiting-logo.svg\",\"contentUrl\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/xiting-logo.svg\",\"width\":1,\"height\":1,\"caption\":\"Xiting\"},\"image\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/XitingAG\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/1345129\\\/\",\"https:\\\/\\\/www.instagram.com\\\/xiting.global\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAP & Compliance: Efficient Risk Minimization with XCW & CRAF - Xiting","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/","og_locale":"en_US","og_type":"article","og_title":"SAP &#038; Compliance: Efficient Risk Minimization with XCW &#038; CRAF","og_description":"SAP Access Control Upgrade and Migration Service 24 July 2020 News Hazhan Salih Basic understanding of SAP authorizations Understanding SAP authorizations, especially with regard to compliance, is crucial for ensuring corporate security and compliance with legal and regulatory requirements. SAP systems offer an extensive and complex authorization structure that enables detailed control over which data [&hellip;]","og_url":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/","og_site_name":"Xiting","article_publisher":"https:\/\/www.facebook.com\/XitingAG","article_modified_time":"2026-05-12T12:11:47+00:00","og_image":[{"width":1024,"height":358,"url":"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy-1024x358.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/","url":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/","name":"SAP & Compliance: Efficient Risk Minimization with XCW & CRAF - Xiting","isPartOf":{"@id":"https:\/\/xiting.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/#primaryimage"},"image":{"@id":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/#primaryimage"},"thumbnailUrl":"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy.png","datePublished":"2026-05-12T12:10:59+00:00","dateModified":"2026-05-12T12:11:47+00:00","breadcrumb":{"@id":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/#primaryimage","url":"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy.png","contentUrl":"https:\/\/xiting.com\/wp-content\/uploads\/2024\/07\/shutterstock_2381539687-copy.png","width":9888,"height":3461},{"@type":"BreadcrumbList","@id":"https:\/\/xiting.com\/en\/news\/sap-compliance-efficient-risk-minimization-with-xcw-craf\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/xiting.com\/en\/"},{"@type":"ListItem","position":2,"name":"News","item":"https:\/\/xiting.com\/en\/news\/"},{"@type":"ListItem","position":3,"name":"SAP &#038; Compliance: Efficient Risk Minimization with XCW &#038; CRAF"}]},{"@type":"WebSite","@id":"https:\/\/xiting.com\/en\/#website","url":"https:\/\/xiting.com\/en\/","name":"Xiting","description":"Your Expert for SAP Security","publisher":{"@id":"https:\/\/xiting.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/xiting.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/xiting.com\/en\/#organization","name":"Xiting","url":"https:\/\/xiting.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiting.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/xiting.com\/wp-content\/uploads\/2019\/08\/xiting-logo.svg","contentUrl":"https:\/\/xiting.com\/wp-content\/uploads\/2019\/08\/xiting-logo.svg","width":1,"height":1,"caption":"Xiting"},"image":{"@id":"https:\/\/xiting.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/XitingAG","https:\/\/www.linkedin.com\/company\/1345129\/","https:\/\/www.instagram.com\/xiting.global\/"]}]}},"_links":{"self":[{"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/news\/62040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/news"}],"about":[{"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/types\/news"}],"author":[{"embeddable":true,"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/users\/77"}],"version-history":[{"count":6,"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/news\/62040\/revisions"}],"predecessor-version":[{"id":62119,"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/news\/62040\/revisions\/62119"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/media\/41575"}],"wp:attachment":[{"href":"https:\/\/xiting.com\/en\/wp-json\/wp\/v2\/media?parent=62040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}