SAP Security Can’t be an Afterthought Anymore 

Every SAP implementation has an unwritten hierarchy of risk. Configuration, data migration and quality usually take priority and rightly so. If the system is not set up correctly with the correct data, the business cannot operate. You only need to look at what happened to SPAR South Africa and Lidl to understand the consequences of getting that wrong. 


Compared to that, a user having slightly more access than they strictly need is a manageable problem. It can be cleaned up after go-live, once the system is stable and the pressure on functional teams has eased. Security becomes the thing that waits not because anyone chooses to deprioritise it, but because the project economics make that outcome almost inevitable 

That logic has been defensible for a long time. Under the ECC named-user licensing model, deferring role design carried governance risk but not immediate financial consequence. The license cost was set at the point of purchase and reviewed annually. An imperfect SAP role design was a compliance problem. It did not carry a licensing cost to it.

Under SAP Cloud ERP Private (Formerly known as RISE with SAP), that calculation changes. The financial consequence of a sub-optimal role design is no longer deferred it begins on the day you go live.

What FUE Changes

SAP’s Full User Equivalent model, which applies to SAP Cloud ERP Private, measures license consumption differently. Instead of assigning license types by job function, FUEs are determined by the SAP authorisation objects assigned to a user. In theory, the more powerful the access, the higher the FUE classification and the higher the cost. 

Most ECC role designs were never built with FUE consumption in mind. They were built to support business processes, manage segregation of duties, and satisfy audit requirements. FUE efficiency was not a design criterion. As a result, when SAP runs their STAR assessment, the mechanism used to establish your baseline FUE requirement at transition it frequently overstates the number of FUEs your organisation actually needs. 

What changes the stakes further is the measurement frequency. Under ECC, license positions were typically reviewed annually. Under SAP Cloud ERP Private, consumption is calculated monthly. Your consumption figure is visible in your SAP for Me portal. If your organisation can see it, so can SAP. SAP has generally allowed organisations some time to stabilise their role design after go-live. That grace period exists because SAP recognises most organisations arrive on SAP Cloud ERP Private without an FUE-optimised design. But it would be unwise to treat that grace period as a strategy. It will not last indefinitely, and the organisations that use it to get their house in order will be in a materially better position than those that do not.

The Real Shift: From Governance Risk to Financial Liability  

This is the change that project sponsors and finance directors need to understand. Security optimisation in ECC was a governance concern important, but often rightly subordinate to keeping the program on track. Under SAP Cloud ERP Private, it becomes a financial one. 

Every month your organisation operates SAP Cloud ERP Private with an unoptimised role design is a month of unnecessary FUE over-consumption. Unlike a compliance issue that may only be identified during a future audit, FUE over-consumption has an immediate financial consequence. From the moment your system goes live, SAP has the contractual right to charge for that excess consumption.

Going live without first understanding your FUE exposure is therefore a financial decision, not simply a governance decision.

What a Seat at the Table Actually Means 

Giving security a seat at the table does not mean adding SAP security to every project workstream or treating role design as a prerequisite to go-live. Projects have constraints, and those constraints are real.

What it does mean is that FUE exposure should be a named input into project planning. The question of whether to address role design before migration and which security activities can be pulled forward regardless of the role design decision. This deserves a deliberate answer, not a default one. That conversation needs to happen early enough to act on.

It also means that the people making decisions about project scope and timeline need to understand what they are trading away when security is That is a different calculation. And it deserves a different response deferred.

In the ECC era, the answer was: governance risk, which is manageable. In the SAP Cloud ERP Private era, the answer includes financial exposure that begins at go-live.

The Organisations That Will Be Better Positioned  

The transition to SAP Cloud ERP Private is still in its early stages for most organisations, giving those that plan ahead a significant advantage. By addressing FUE licensing early in the migration journey, organisations are far more likely to avoid costly over-subscription after go-live. This becomes increasingly important as the end of SAP ECC mainstream maintenance approaches. As more organisations rush to migrate, demand for experienced SAP consultants is expected to outstrip supply, making it harder and more expensive to address licensing and role design issues late in the programme. 

Security cannot continue to be the thing that waits. The financial model has changed. The approach needs to follow. 

Thinking About Your FUE Exposure?  

If your organisation is planning a migration to SAP Cloud ERP Private or has already moved and your FUE consumption is higher than expected Soterion can help you understand where the exposure is and what it would take to address it. It starts with a conversation. 

Get in touch with the Soterion team. 

You may find this interesting