Get in Touch

Course Outline

Session 1 (4 hours)

Module 1 – S/4HANA Fundamentals for Auditors (2 hours)

  • Core architecture components, including ABAP, Fiori interfaces, and authorization catalogs and roles.
  • Key architectural distinctions from ECC systems:
    • Business Partner (BP) model integration.
    • Universal Journal structure (ACDOCA table).
    • Flexible workflow capabilities.
  • Current mapping of Audit Information Services to transactions and equivalent functions within Fiori applications.

Module 2 – Access Control, Roles, and Essential Segregation of Duties (2 hours)

  • Management of user accounts and authorization tools: PFCG, SUIM, SU53, and SU24 (transaction-specific authorizations).
  • Structure of Fiori catalogs and roles, including application identifiers, catalog assignments, and launchpad spaces.
  • Overview of the fundamental Segregation of Duties (SoD) matrix and common audit findings, such as conflicting permissions for creation and approval within a single role.

Session 2 (4 hours)

Module 3 – Security Logs and Audit Trails (3 hours)

  • Configuration and utilization of the Security Audit Log (SM19/SM20): activation procedures, filter setup, and data retrieval.
  • Analysis of system usage statistics, active sessions, and peak loads via STAD and ST03N.
  • Principles and application scenarios for Read Access Logging (RAL).
  • Standards for evidence retention, documentation, and data export suitable for government auditing requirements.

Module 4 – Configuration Modifications and Sensitive Data Handling (1 hour)

  • Review of change documents via SCU3 and change policies using SCC4.
  • Examination of critical system parameters (RZ10/RZ11) and methods for documenting evidence.

Session 3 (4 hours)

Module 5 – Process Controls in Finance, Materials Management, and Sales (FI/MM/SD) within S/4 (4 hours)

  • Finance (FI): Tolerance limits, OB52 period management, entry segregation, and journal approval workflows.
  • Materials Management (MM): Release strategies, monetary limits, single-source procurement protocols, and condition contract modifications.
  • Sales and Distribution (SD): Credit limit management via FSCM and handling of price or condition changes.
  • Business Partner (BP): Controls governing partner creation and modification, with emphasis on fiscal and banking data sensitivity.
  • Methodologies for risk-driven sampling and evidence selection for government compliance audits.

Session 4 (4 hours)

Module 6 – Practical Application Workshop and Reporting (3 hours)

  • Execution of role elevation and access modification for a critical system user.
  • Tracing operational transactions (procurement/sales) and retrieving audit evidence using SM20 and SCU3.
  • Documentation of audit findings, including capture methods and data exports.
  • Development of work papers and establishment of traceability standards for government review.

Module 7 – Conclusion and Strategic Action Plan (1 hour)

  • Application of the S/4 internal control checklist.
  • Prioritization of identified findings and development of corrective recommendations.

Deliverables:

  • Comprehensive checklist comprising 20+ controls across FI, MM, SD, and BP modules for government audit preparation.
  • Concise reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N tools.

Requirements

  • Demonstrated knowledge of fundamental audit methodologies
  • Practical experience operating within SAP environments
  • Working familiarity with established compliance and control frameworks

Target Audience

  • Government auditors
  • Internal control specialists
  • SAP security consultants
  • Compliance officers responsible for federal requirements
 16 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories