Course Outline
Session 1 (4h)
Module 1 – S/4HANA Fundamentals for Auditors (2h)
- Core architecture (ABAP, Fiori, catalogs/roles).
-
Key Differences from ECC:
- Business Partner model.
- Universal Journal (ACDOCA).
- Flexible workflows.
- Current AIS locations: transaction codes and Fiori equivalents.
Module 2 – Access, Roles, and Essential SoD (2h)
- User management, PFCG, SUIM, SU53, SU24 (authorization analysis by transaction code).
- Fiori catalogs and roles (app-id, catalog, space).
- Fundamental SoD matrix and common audit findings (e.g., creation and release within the same role).
Session 2 (4h)
Module 3 – Security Logs and Traces (3h)
- Security Audit Log (SM19/SM20): activation, filtering, and interpretation.
- STAD/ST03N: usage statistics, session analysis, and peak activity identification.
- Read Access Logging (RAL): conceptual overview and application scenarios.
- Best practices for evidence retention and data export.
Module 4 – Configuration Changes and Sensitive Data (1h)
- Change Documents (SCU3) and Change Policy (SCC4).
- Critical parameters (RZ10/RZ11): review and evidence gathering.
Session 3 (4h)
Module 5 – Process Controls (FI/MM/SD) in S/4 (4h)
- FI: Tolerance settings, open periods (OB52), entry segregation, and journal approval workflows.
- MM: Release strategies, limit configurations, single-source purchasing, and condition changes.
- SD: Credit limits (FSCM Credit Management) and price/condition adjustments.
- BP: Controls on creation/modification, and fiscal/banking data sensitivity.
- Risk-based sampling and selection methodologies.
Session 4 (4h)
Module 6 – Comprehensive Laboratory + Reporting (3h)
- Review and analyze roles and access for a critical user.
- Trace operational transactions (buy/sell) and gather evidence (SM20/SCU3).
- Document findings using specific captures and exports.
- Prepare working papers and ensure traceability.
Module 7 – Closure and Action Plan (1h)
- Internal control checklist specific to S/4.
- Prioritization of findings and formulation of recommendations.
Deliverables:
- A comprehensive checklist of 20+ controls (FI/MM/SD/BP).
- A quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N.
Requirements
- A foundational understanding of core auditing principles
- Practical experience with SAP systems
- Familiarity with compliance standards and control frameworks
Target Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
Testimonials (2)
It was straight to the point and more practical
Lungelo Ndlela - SNG Grant Thornton
Course - SAP S/4 Hana (S/4Hana)
His calm and collected voice even though at points he was frustrated with the system, but kept his cool…