Get in Touch
 Duration 16 hours

Course Outline

Session 1 (4h)

Module 1 – S/4HANA Fundamentals for Auditors (2h)

  • Foundational architecture components, including ABAP, Fiori, and catalogs/roles.
  • Significant differences compared to ECC:
    • Implementation of the Business Partner concept.
    • Introduction of the Universal Journal (ACDOCA).
    • Enhanced flexibility in workflows.
  • Current locations for audit information (AIS), including transaction equivalents within Fiori.

Module 2 – Access, Roles, and Essential SoD (2h)

  • Management of users via PFCG, SUIM, SU53, and SU24 (authorization checks by transaction code).
  • Configuration of Fiori catalogs and roles (app-id, catalog, space).
  • Basic SoD matrices and common findings, such as conflicting creation and release functions within a single role.

Session 2 (4h)

Module 3 – Security Logs and Traces (3h)

  • Utilizing the Security Audit Log (SM19/SM20): activation, filtering, and interpretation.
  • Analyzing usage statistics, sessions, and performance peaks via STAD/ST03N.
  • Understanding Read Access Logging (RAL): concepts and application scenarios.
  • Best practices for retaining and exporting audit evidence.

Module 4 – Configuration Changes and Sensitive Data (1h)

  • Tracking changes using SCU3 (change documents) and managing policies with SCC4.
  • Reviewing critical parameters via RZ10/RZ11 and documenting evidence.

Session 3 (4h)

Module 5 – Process Controls (FI/MM/SD) in S/4 (4h)

  • FI: Tolerance settings, period management (OB52), segregation in journal entries, and workflow-based approvals.
  • MM: Purchase order release strategies, limits, single-source supplier rules, and condition changes.
  • SD: Credit limits (FSCM Credit Management) and modifications to pricing or conditions.
  • BP: Controls on creation and exchange, focusing on fiscal and banking sensitivities.
  • Applying risk-driven sampling and selection methods.

Session 4 (4h)

Module 6 – Comprehensive Laboratory and Reporting (3h)

  • Simulating role elevation and access expansion for a critical user.
  • Tracing specific operations (buy/sell) and gathering evidence (SM20/SCU3).
  • Documenting findings through captures and data exports.
  • Drafting working papers and ensuring full traceability.

Module 7 – Closure and Action Planning (1h)

  • Reviewing the internal control checklist specific to S/4HANA.
  • Prioritizing findings and formulating actionable recommendations.

Deliverables:

  • A comprehensive checklist containing over 20 controls for FI, MM, SD, and BP.
  • A quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N.

Requirements

  • A solid foundation in basic auditing principles
  • Practical experience working with SAP systems
  • Knowledge of compliance standards and control frameworks

Target Audience

  • Auditors
  • Internal control specialists
  • SAP security consultants
  • Compliance officers

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories