Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
R/3 Foundations for Audit Purposes
- Core architecture components, including the ABAP stack, SAP GUI, and the client concept.
- Distinguishing SAP R/3 from legacy systems through its modular design (FI, MM, SD).
- Navigation techniques and classic transactions tailored for audit workflows.
Access Management, Roles, and SoD Essentials
- Managing user authorizations using key transactions such as PFCG, SU01, SUIM, SU53, and SU24.
- Designing roles and identifying functions that are critical to audit observations.
- Understanding basic SoD matrices and recognizing common risk scenarios, such as combining invoice creation and approval within a single role.
Monitoring via Security Logs and Traces
- Working with the Security Audit Log (SM19/SM20), covering activation, filtering strategies, and reporting capabilities.
- Analyzing system usage, session data, and workload using STAD and ST03N.
- Best practices for retaining, exporting, and managing audit evidence.
Configuration Management and Sensitive Data
- Tracking changes via SCU3 (change documents) and managing client settings through SCC4.
- Identifying and monitoring critical system parameters in RZ10 and RZ11.
Process Controls in R/3 (FI/MM/SD)
- FI: Managing tolerances, posting periods (OB52), and journal entry approval workflows.
- MM: Implementing release strategies, enforcing purchase order limits, and managing single supplier controls.
- SD: Monitoring credit limits, pricing adjustments, and condition changes.
- Applying audit sampling techniques to effectively test process integrity.
Hands-on Laboratory and Reporting
- Conducting a comprehensive review of roles and authorizations for critical users.
- Tracing specific operations (such as purchasing and sales) to gather concrete audit evidence via SM20 and SCU3.
- Documenting findings effectively using screenshots and data exports.
- Preparing detailed working papers and ensuring full traceability.
Conclusion and Action Planning
- Utilizing an internal control checklist tailored for SAP R/3.
- Prioritizing audit findings and formulating actionable recommendations.
Key Deliverables
- A comprehensive checklist covering over 20 controls across FI, MM, and SD modules.
- A quick reference guide for essential transactions: SM19/SM20, SUIM, SCU3, and STAD/ST03N.
Requirements
- A solid grasp of fundamental auditing principles
- Prior experience working with SAP systems
- Working knowledge of compliance and internal control frameworks
Target Audience
- Internal and external auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
16 Hours
Testimonials (2)
It was straight to the point and more practical
Lungelo Ndlela - SNG Grant Thornton
Course - SAP S/4 Hana (S/4Hana)
His calm and collected voice even though at points he was frustrated with the system, but kept his cool…