ArtimIS
ArtimIS is a French SAP consulting firm specializing in Governance, Risk, and Compliance (GRC), authorization security, identity access governance, and cybersecurity for enterprise clients. Founded in 2017 and acquired by oXya in 2024, it operates across France, Tunisia, and Canada.
- Company typePrivate
- Founded2017
- HeadquartersParis, France
- Headcount11–50
- GTM typeB2B
- OfferingServices
What ArtimIS does
ArtimIS is a French consulting firm founded in 2017 in Paris that specializes in SAP Governance, Risk, and Compliance (GRC), authorization security, identity and access governance (IAG), and cybersecurity services for enterprise clients running SAP ERP environments including S/4HANA and SAP Fiori. The firm delivers advisory and implementation services across six practice areas: GRC strategy and innovation, regulatory compliance (SOx/LSF, Sapin II, RGPD), internal audit and internal control support, access governance and Segregation of Duties (SoD) management, GRC application implementation (SAP GRC Access Control, Process Control, Risk Management, and SAP IAG), and cybersecurity and data protection. ArtimIS also partners with Saviynt for IAG tooling and operates an internal ArtimIS Academy training program to develop SAP authorization consultants.
The firm targets large enterprises (over 5,000 employees, revenue above €1.5B), mid-size enterprises (250-5,000 employees), and select public sector organizations in France, with an industry concentration in energy, transport, healthcare, aerospace, manufacturing, and consumer goods. Named clients include L'Oréal, Schneider Electric, Safran, EDF, Engie, GRT Gaz, RTE, CMA CGM, APHP, Smurfit Kappa, Sercel, Markem-Imaje, Artelia, Guerbet, Kion Group, and Soufflet. ArtimIS operates from five locations — Paris (headquarters), Nantes, Lyon, Tunis (ArtimIS TunIS near-shoring subsidiary opened March 2019), and Montréal (opened 2025) — and reports 36-45+ consultants representing 11+ nationalities and 9 languages, achieving €3M in revenue by late 2022. Pricing is quote-based on project scope, consultant seniority, and engagement duration, with both short-term missions and multi-year accompaniment contracts.
In August 2024, ArtimIS was acquired by oXya, a global leader in managed services and cloud solutions for SAP applications, combining ArtimIS's GRC, IAG, and SAP cybersecurity expertise with oXya's managed services infrastructure. Following the acquisition, ArtimIS operates as a subsidiary of oXya while maintaining its brand identity and GRC-focused service portfolio. The firm is GDPR/RGPD compliant with Binding Corporate Rules governing data transfers to Tunis and oXya entities, and reports a 50% gender balance among its team.
ArtimIS firmographics
Firmographics- Name
- ArtimIS
- Legal name
- ArtimIS SAS
- Website
- https://artimis.fr
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ArtimIS is a French SAP consulting firm specializing in Governance, Risk, and Compliance (GRC), authorization security, identity access governance, and cybersecurity for enterprise clients. Founded in 2017 and acquired by oXya in 2024, it operates across France, Tunisia, and Canada.
- Ownership category
- akta.pro rank
ArtimIS industry classification
Industry- Product category
- SAP GRC Consulting & Implementation Services
- NAICS
- Management, Scientific, and Technical Consulting Services (5416), Computer Systems Design and Related Services (5415), Computer Systems Design Services (541512)
- SIC
- Services-Management Consulting Services (8742), Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- ERP Implementation & Systems Integration Services (BPAEAGAA)
- akta.pro secondary industry
- Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) (HDAAAMAE)
Keywords
Where ArtimIS is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices5 records
Markets served
ArtimIS business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D
Revenue model
- Consulting Services: Professional consulting services for GRC strategy, compliance advisory, access governance, internal audit support, and cybersecurity. Services include short-term missions and long-term accompaniment engagements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements tailored to client needs |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
ArtimIS product offering
Product offeringCore offering
ArtimIS is a consulting firm that advises and implements Governance, Risk, and Compliance (GRC) solutions for SAP environments. The firm sells advisory engagements, GRC application implementation services, access governance and SAP authorization security, and cybersecurity and data protection services to enterprises running SAP ERP, SAP S/4HANA, and SAP Fiori. Engagements cover SOx/LSF, Sapin II, and RGPD compliance programs, segregation of duties (SoD) analysis, internal audit support, and managed TMA activities.
Product overview
ArtimIS is a French consulting firm specializing in GRC (Governance, Risk, and Compliance) advisory services, particularly focused on SAP environments. The company offers a portfolio of service offerings including GRC Strategy & Innovation, Compliance Advisory, Internal Audit & Internal Control Support, Access Governance Advisory, GRC Application Implementation & Services, and Cybersecurity & Data Protection Services. ArtimIS also provides implementation services for SAP GRC solutions including SAP GRC Access Control, SAP GRC Process Control, SAP GRC Risk Management, and SAP IAG (Identity Access Governance). They partner with SAP and Saviynt to deliver these solutions. The company operates an internal training program called ArtimIS Academy for consultant onboarding.
Differentiator
Problem solved
Functional benefit
Products and services
- GRC Strategy & Innovation Advisory services for defining GRC frameworks (cadre de référence), conducting GRC maturity assessments, and selecting appropriate GRC tools for enterprise SAP environments.
- Compliance Advisory Advisory services helping organizations achieve and maintain compliance with SOx/LSF, Sapin II, and RGPD regulations through policy, process, and control design.
- Internal Audit & Internal Control Support Support services for internal audit teams and internal control functions, including audit execution, internal control design, and operational support.
- Access Governance Advisory Advisory services for segregation of duties (SoD) governance, identity and access governance (IAG), secure access management, and SAP authorization security across ERP environments.
- GRC Application Implementation & Services Implementation, deployment, and managed services for SAP GRC solutions (including SAP GRC Access Control, Process Control, Risk Management, and SAP IAG), including project management and change management support.
- Cybersecurity & Data Protection Services Cybersecurity services for SAP environments including patch management, identity federation, data protection (RGPD), and security supervision/monitoring.
Quantifiable outcome
- 20-30 consulting missions completed annually across multiple industries
- +2 more outcomes
Companies that use ArtimIS
Customer profileNamed customers18 records
Segments4 records
Ideal customer profiles3 records
ArtimIS technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
ArtimIS partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- oXyacoreIn August 2024, ArtimIS joined oXya, a global leader in managed services and cloud solutions for SAP. This strategic acquisition enables ArtimIS to expand its offerings by combining its GRC, IAG, and SAP cybersecurity expertise with oXya's infrastructure and innovation capabilities.
Scale indicators7 records
Recent moves12 records
Expansion highlights6 records
ArtimIS competitors and assessment
Company assessmentBroad incumbents
- Accenture: Global consulting leader with a dedicated SAP business group that delivers GRC, security, and S/4HANA programs to many of the same CAC-40 and pan-European clients as ArtimIS.
- KPMG: Big 4 firm with a dedicated SAP-enabled GRC and risk advisory practice, including controls automation and SoD analytics, frequently competing for SAP compliance work in France and Europe.
- EY (Ernst & Young): Big 4 firm with SAP GRC, risk, and cybersecurity advisory practices that overlap with ArtimIS's SoD, IAG, and SOx/LSF compliance services, especially for French and pan-European regulated enterprises.
- IBM Consulting: Global consulting arm delivering SAP S/4HANA, security, and GRC services, including identity and access governance, to large multinational clients overlapping ArtimIS's target segments.
- Capgemini: Global SI with one of the largest SAP S/4HANA and application services practices, including SAP GRC and identity/access governance; competes for the same enterprise transformation budgets at much greater scale.
Direct peers
- Wavestone: French-origin consulting firm with a dedicated cybersecurity, risk, and compliance practice that overlaps with ArtimIS's SAP GRC and access governance advisory work.
- Protiviti: Global risk and compliance consulting firm with an established internal audit, GRC technology, and SAP-focused risk advisory offering that mirrors ArtimIS's access governance and SoD positioning.
- Sopra Steria: French-headquartered IT services group with a sizable SAP practice covering GRC, S/4HANA, and authorization services; competes for the same French large-enterprise SAP GRC mandates as ArtimIS.
- Devoteam: European tech consulting firm with a strong SAP and cloud transformation practice, including SAP S/4HANA migration and adjacent GRC/security advisory engagements.
Regional players
- Onepoint: Large French consulting and technology firm with risk, compliance, and SAP transformation capabilities; competes for French enterprise GRC and digital transformation mandates.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
ArtimIS social profiles
Digital presenceArtimIS compliance and trust
Trust signalCompliance2 records
ArtimIS financial estimates
Financial estimateRevenue estimate
Valuation estimate
ArtimIS leadership team
Management profileNumber of profiles
Profiles6 records
ArtimIS subsidiaries and ownership
Company hierarchySubsidiaries1 record
ArtimIS funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ArtimIS M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ArtimIS
What does ArtimIS do?
ArtimIS is a consulting firm that advises and implements Governance, Risk, and Compliance (GRC) solutions for SAP environments. The firm sells advisory engagements, GRC application implementation services, access governance and SAP authorization security, and cybersecurity and data protection services to enterprises running SAP ERP, SAP S/4HANA, and SAP Fiori. Engagements cover SOx/LSF, Sapin II, and RGPD compliance programs, segregation of duties (SoD) analysis, internal audit support, and managed TMA activities.
Is ArtimIS a public or private company?
ArtimIS is a private company. It is classified as corporate owned and is currently operating.
When was ArtimIS founded?
ArtimIS was founded in 2017. It employs 11 to 50 people.
Where is ArtimIS based?
ArtimIS is headquartered in Paris, France, in the Europe region.
How does ArtimIS make money?
One revenue line is on record: consulting Services.
Who are ArtimIS's main competitors?
Broad incumbents on record are Accenture, KPMG, EY (Ernst & Young), IBM Consulting and Capgemini. Direct peers are Wavestone, Protiviti, Sopra Steria and Devoteam. Onepoint is listed as a regional player.
Does ArtimIS have an API?
No public API is recorded for ArtimIS.
What industry is ArtimIS in?
ArtimIS's product category is SAP GRC Consulting & Implementation Services. Its primary akta.pro industry code is BPAEAGAA, ERP Implementation & Systems Integration Services, with a secondary code of HDAAAMAE, Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001). Its NAICS code is 5416 and its SIC code is 8742.