Course Outline
-
Basic architecture (ABAP, Fiori, catalogs/roles).
-
Key Changes vs. ECC:
-
Business Partner.
-
Universal Journal (ACDOCA).
-
Workflows flexibles.
-
-
AIS location today: transactions and equivalents in Fiori.
-
Users, PFCG, SUIM, SU53, SU24 (authorizations by tcode).
-
Fiori catalogs and roles (app-id, catalog, space).
-
Basic SoD matrix and typical findings (e.g. creation and release in the same role).
-
Security Audit Log (SM19/SM20): activation, filters, reading.
-
STAD/ST03N: usage statistics, sessions and peaks.
-
Read Access Logging (RAL): concept and when to use it.
-
Good practices for evidence retention and export.
-
SCU3 (change documents), SCC4 (change policy).
-
Critical parameters (RZ10/RZ11): reading and evidence.
-
FI: tolerances, OB52 (periods), segregation in entries, journal approval (workflow).
-
MM: release strategies, limits, single supplier, changes in conditions.
-
SD: Credit limits (FSCM Credit Management), price/condition changes.
-
BP: controls on creation/exchange, fiscal/banking sensitivity.
-
Risk-driven sampling and selection techniques.
-
Raise roles and access of a critical user.
-
Trace operation (buy/sell) and obtain evidence (SM20/SCU3).
-
Document findings with catches and exports.
-
Preparation of working papers and traceability.
-
Internal control checklist in S/4.
-
Prioritization of findings and recommendations.
-
Checklist of 20+ controls (FI/MM/SD/BP).
-
Quick guide to SM19/SM20, SUIM, SCU3, STAD/ST03N.
Requirements
- An understanding of basic auditing principles
- Experience with SAP systems
- Familiarity with compliance and control frameworks
Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
Testimonials (4)
Teacher knolage
Collin Sampson
Course - SAP S/4HANA Overview (S4H00)
I liked the fact that the trainer was very flexible and offered information about subjects that were not included in the initial material. I liked his experience in other projects and the tips and tricks resulted from this experience. The training was interactive and even though the exercises were predefined, we could take the exercise in another direction than previously defined.
Maria-Cristina Socol - NTT DATA Romania S.A.
Course - SAP S/4 Hana (S/4Hana)
We have learnt so many things that we didn't know before.
Lebogang Kgosiesele - Lucara Botswana
Course - SAP S/4 HANA PP (Production Planning)
Ayman was a very good trainer. He explained our doubts and was very easy to understand. He gave satisfactory answer to all questions we raised.