Log in to save this article and keep your favorite resources in one place.
This Partner Insight was authored by Joe Markgraf, Founder of Markgraf Consulting.
Transformation was never supposed to change who’s in control of the technology. But over time, it often does.
A storm rolls through a utility’s service territory. Crews are staged, outage tickets are queued, and the SAP platform behind the whole operation is doing exactly what it was built to do. Customer records are accurate, billing is available, and security controls are holding. Nothing is technically broken.
Yet restoring service for a single household stalls because customer operations, infrastructure, security, and finance each have a legitimate claim on who makes the call.
That gap already has an owner on paper. It’s called the Roles and Responsibilities document, or R&R, and it comes with every RISE with SAP contract. Most organizations read it once, during signing, and never open it again.
Precise on Day 1
The R&R is a formal contractual exhibit, a task-by-task matrix that assigns every operational responsibility in the environment — infrastructure, security, application support, custom code, integration — to SAP, to the customer, or to both. Line by line, it answers the exact question that stalls a storm response: who owns this?
At SAP and SAP National Security Services (SAP NS2), I helped design the cloud reference architecture that would later become part of RISE with SAP, including the R&R framework itself. At signing, the answer is precise because organizations negotiate this document hard. It’s worth millions of dollars across the life of the contract.
The problem begins the day after signing. The R&R is frozen the moment it’s executed. The organization it describes is not.
Every finance team already understands amortization — a contract’s recorded value declining across its life on a fixed schedule, whether or not anyone updates the paperwork. Almost none apply that thinking to what the contract says about who’s actually in charge. We call this Ownership Amortization: the governance value of a document quietly declining from the day it’s signed, even as the document itself never changes.
Every acquisition, every AI initiative, every security program, every regulatory change, and every retirement moves a decision from one desk to another. None of this gets reflected in the one document that’s supposed to say who owns what now.
RISE customers see this most clearly, because SAP put it in writing. Utilities running through a hyperscaler-hosted managed services partner or their own private cloud know it under a different name, whether a master services agreement (MSA), a RACI chart, or an internal operating agreement. Whatever it’s called, ownership amortizes the same way.
Why Utilities Feel This First
Utilities feel this earlier than most industries because the people quietly holding the real version of this document together are retiring. These are the ones who know the R&R says one thing while the actual process has moved elsewhere.
When they leave, the organization loses the last person who could see how far ownership had already amortized away from what the document still claims.
And a regulator reviewing an outage, a security incident, or an audit finding will not accept “the contract says it was shared” as an answer. They will ask who was responsible and expect a name.
Getting ahead of that question, instead of discovering it during an audit, depends on who’s actually paying attention before anything breaks.
Where Most Advisory Work Stops Short
Traditional advisory models rarely reward closing this kind of gap quickly. The larger the firm, the more its business model depends on ambiguity lasting long enough to bill against — another change order, another year of managed services layered on top of a document nobody wants to reopen. In that model, speed and candor about the R&R are a threat.
We recently scoped a multi-month remediation engagement for a utility governance, risk, and compliance (GRC) tooling and identity governance tooling had drifted so far from how access was actually being provisioned that nobody could say with confidence who owned an unmitigated user until one surfaced in an audit. Unwinding it took months and ran into six figures. Nobody had kept the ownership question current since the systems went live.
A firm with that incentive structure can afford to let the gap sit. We can’t, and we don’t want to. Being small enough to send the person who helped design the reference architecture, instead of a team assembled after the contract is signed, was never a limitation or a workaround. It is the entire point.
Ownership Amortization is a governance problem, and it’s the mechanism behind a larger pattern: any document that once answered “who’s in charge” has stopped being true, whether that’s an R&R, an M&A integration plan, or an AI governance charter. SAP is simply where it’s easiest to see and prove.
If any of this sounds familiar inside your own organization, that recognition is exactly what an Executive Operating Model Assessment is built to test: governance, accountability, and decision rights, examined against the organization you have today, rather than the one described in the agreement you signed.
Joe Markgraf is the Founder of Markgraf Consulting, an advisory practice focused on SAP security, governance, and operational resilience.
You Might Be Interested In
Log in to save this article and keep your favorite resources in one place.
Log in to save this article and keep your favorite resources in one place.
Log in to save this article and keep your favorite resources in one place.
Log in to save this article and keep your favorite resources in one place.