Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 16 hours
Course Outline
Session 1 (4h)
Module 1 – S/4HANA Fundamentals for Auditors (2h)
- Foundational architecture components, including ABAP, Fiori, and catalogs/roles.
- Significant differences compared to ECC:
- Implementation of the Business Partner concept.
- Introduction of the Universal Journal (ACDOCA).
- Enhanced flexibility in workflows.
- Current locations for audit information (AIS), including transaction equivalents within Fiori.
Module 2 – Access, Roles, and Essential SoD (2h)
- Management of users via PFCG, SUIM, SU53, and SU24 (authorization checks by transaction code).
- Configuration of Fiori catalogs and roles (app-id, catalog, space).
- Basic SoD matrices and common findings, such as conflicting creation and release functions within a single role.
Session 2 (4h)
Module 3 – Security Logs and Traces (3h)
- Utilizing the Security Audit Log (SM19/SM20): activation, filtering, and interpretation.
- Analyzing usage statistics, sessions, and performance peaks via STAD/ST03N.
- Understanding Read Access Logging (RAL): concepts and application scenarios.
- Best practices for retaining and exporting audit evidence.
Module 4 – Configuration Changes and Sensitive Data (1h)
- Tracking changes using SCU3 (change documents) and managing policies with SCC4.
- Reviewing critical parameters via RZ10/RZ11 and documenting evidence.
Session 3 (4h)
Module 5 – Process Controls (FI/MM/SD) in S/4 (4h)
- FI: Tolerance settings, period management (OB52), segregation in journal entries, and workflow-based approvals.
- MM: Purchase order release strategies, limits, single-source supplier rules, and condition changes.
- SD: Credit limits (FSCM Credit Management) and modifications to pricing or conditions.
- BP: Controls on creation and exchange, focusing on fiscal and banking sensitivities.
- Applying risk-driven sampling and selection methods.
Session 4 (4h)
Module 6 – Comprehensive Laboratory and Reporting (3h)
- Simulating role elevation and access expansion for a critical user.
- Tracing specific operations (buy/sell) and gathering evidence (SM20/SCU3).
- Documenting findings through captures and data exports.
- Drafting working papers and ensuring full traceability.
Module 7 – Closure and Action Planning (1h)
- Reviewing the internal control checklist specific to S/4HANA.
- Prioritizing findings and formulating actionable recommendations.
Deliverables:
- A comprehensive checklist containing over 20 controls for FI, MM, SD, and BP.
- A quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N.
Requirements
- A solid foundation in basic auditing principles
- Practical experience working with SAP systems
- Knowledge of compliance standards and control frameworks
Target Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
Testimonials (2)
It was straight to the point and more practical
Lungelo Ndlela - SNG Grant Thornton
Course - SAP S/4 Hana (S/4Hana)
His calm and collected voice even though at points he was frustrated with the system, but kept his cool…