Get in Touch

Course Outline

Session 1 (4h)

Module 1 – S/4HANA Fundamentals for Auditors (2h)

  • Core architecture (ABAP, Fiori, catalogs/roles).
  • Key Differences from ECC:
    • Business Partner model.
    • Universal Journal (ACDOCA).
    • Flexible workflows.
  • Current AIS locations: transaction codes and Fiori equivalents.

Module 2 – Access, Roles, and Essential SoD (2h)

  • User management, PFCG, SUIM, SU53, SU24 (authorization analysis by transaction code).
  • Fiori catalogs and roles (app-id, catalog, space).
  • Fundamental SoD matrix and common audit findings (e.g., creation and release within the same role).

Session 2 (4h)

Module 3 – Security Logs and Traces (3h)

  • Security Audit Log (SM19/SM20): activation, filtering, and interpretation.
  • STAD/ST03N: usage statistics, session analysis, and peak activity identification.
  • Read Access Logging (RAL): conceptual overview and application scenarios.
  • Best practices for evidence retention and data export.

Module 4 – Configuration Changes and Sensitive Data (1h)

  • Change Documents (SCU3) and Change Policy (SCC4).
  • Critical parameters (RZ10/RZ11): review and evidence gathering.

Session 3 (4h)

Module 5 – Process Controls (FI/MM/SD) in S/4 (4h)

  • FI: Tolerance settings, open periods (OB52), entry segregation, and journal approval workflows.
  • MM: Release strategies, limit configurations, single-source purchasing, and condition changes.
  • SD: Credit limits (FSCM Credit Management) and price/condition adjustments.
  • BP: Controls on creation/modification, and fiscal/banking data sensitivity.
  • Risk-based sampling and selection methodologies.

Session 4 (4h)

Module 6 – Comprehensive Laboratory + Reporting (3h)

  • Review and analyze roles and access for a critical user.
  • Trace operational transactions (buy/sell) and gather evidence (SM20/SCU3).
  • Document findings using specific captures and exports.
  • Prepare working papers and ensure traceability.

Module 7 – Closure and Action Plan (1h)

  • Internal control checklist specific to S/4.
  • Prioritization of findings and formulation of recommendations.

Deliverables:

  • A comprehensive checklist of 20+ controls (FI/MM/SD/BP).
  • A quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N.

Requirements

  • A foundational understanding of core auditing principles
  • Practical experience with SAP systems
  • Familiarity with compliance standards and control frameworks

Target Audience

  • Auditors
  • Internal control specialists
  • SAP security consultants
  • Compliance officers
 16 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories