← Back to home

About GRC Aura

Built by GRC Advisory — SAP Security & GRC consultancy with 20+ years of authorization, audit, and license-optimization experience.

Built by the team behind Poland's largest SAP GRC deployment

GRC Advisory has delivered SAP GRC, Access Control, and compliance projects to more than 100 organizations across Poland and Europe, including the largest SAP GRC Access Control deployment in Poland. We know where license math breaks down because we have been cleaning up after it for years.

Aura is what we wished we had on every one of those rollouts: not another Excel export, but a live view of which assigned access is actually used — and which PUPM license tiers that usage actually justifies.

Visit grcadvisory.com →

100+
SAP GRC projects delivered
#1
Largest SAP GRC AC deployment in Poland
20+
Years of SAP expertise
EU
Active in PL, DACH, Nordics

Why we built GRC Aura

In 2024, while running an SAP S/4HANA Cloud Public Edition migration for a 1,500-user manufacturer, we hit a recurring problem: their SAP licensing bill grew 40% post-migration, even though the actual user behavior had not changed. The reason: under PUPM, every user assigned to an Advanced Business Catalog gets billed at the highest tier — even if 90% of them only use Core-level functionality.

We tried to solve it with Excel, SAP STAR reports, and ABAP queries. None gave a clear, actionable picture. So we built one. GRC Aura is the tool we wished existed — connecting directly to SAP Cloud ERP and showing actual usage per user, per Business Catalog, per FUE persona — so every PUPM tier you pay for is backed by real activity.

In 12 weeks of pilot deployments, our customers identified 25–35% reduction potential in annual SAP licensing spend. That is GRC Aura's promise: not another dashboard, but the difference between paying for assigned access and paying for actual access.

Who's behind GRC Aura

Filip Nowak

Founder & CEO, GRC Advisory

15+ years in SAP Security, GRC Access Control, and S/4HANA authorization design. Led GRC Access Control deployments for 30+ enterprises across DACH, Nordics, and CEE. CISA, CISM, ISO 27001 Lead Auditor.

LinkedIn →

GRC Advisory Team

SAP Security & License Engineers

Senior SAP consultants with combined 80+ years of experience in authorization design, role refactoring, segregation of duties, and FUE/PUPM analysis. Active in SAP Community and SAP Partner Network.

Meet the team →

Engineering & Research

Product Development

Engineers and SAP architects building GRC Aura on SAP BTP. Continuous research into SAP Cloud ERP licensing rules, Business Catalog evolution, and authorization analytics — feeding the rule engine that powers Aura.

Talk to engineering →

Certifications & partnerships

ISO 27001

Information Security Management certified

SAP Partner

Listed in SAP Partner Finder

GDPR Compliant

EU-based data processing & storage

SAP BTP

Built natively on SAP Business Technology Platform

Want to work with us?

Whether you need GRC Aura for your own SAP tenant or want to explore a partnership, we're happy to talk.