Course Outline
Session 1 (4 hours)
Module 1 – R/3 Fundamentals for Auditors (2 hours)
- System architecture overview, including the ABAP stack, SAP GUI interface, and client management concepts.
- Distinctions between legacy environments and S/4HANA, emphasizing modular functional areas such as Financials (FI), Materials Management (MM), and Sales and Distribution (SD).
- Navigating standard transactions to support audit objectives.
Module 2 – Access Control, Roles, and Segregation of Duties (2 hours)
- User administration and authorization management using PFCG, SU01, SUIM, SU53, and SU24 tools.
- Role design principles and identification of audit-critical functions within R/3 for government operations.
- Overview of the Segregation of Duties (SoD) matrix, including common compliance findings such as dual authorization for invoice creation and approval within a single role.
Session 2 (4 hours)
Module 3 – Security Logging and Trace Analysis (3 hours)
- Security Audit Log configuration via SM19/SM20, including filter settings and reporting capabilities.
- Utilization of STAD and ST03N for usage statistics, session monitoring, and workload analysis.
- Best practices for retaining audit evidence and exporting logs for review.
Module 4 – Configuration Changes and Sensitive Data Management (1 hour)
- Review of change documents via SCU3 and client-level configurations using SCC4.
- Identification and monitoring of critical system parameters through RZ10/RZ11.
Session 3 (4 hours)
Module 5 – Process Controls in FI/MM/SD within R/3 (4 hours)
- Financials (FI): Management of tolerances, posting periods (OB52), and journal entry approval workflows.
- Materials Management (MM): Implementation of release strategies, purchase order thresholds, and supplier-specific controls.
- Sales and Distribution (SD): Oversight of credit limits, pricing modifications, and condition monitoring.
- Audit sampling methodologies for process validation.
Session 4 (4 hours)
Module 6 – Comprehensive Laboratory Exercise and Reporting (3 hours)
- Evaluation of roles and authorizations assigned to critical user accounts.
- Tracing transactional operations (procurement and sales) and collecting audit evidence via SM20 and SCU3 for government compliance.
- Documentation of findings using screenshots and system exports.
- Preparation of working papers and establishment of traceability.
Module 7 – Program Closure and Action Plan (1 hour)
- Application of an internal control checklist specific to R/3.
- Prioritization of identified findings and formulation of corrective recommendations.
Deliverables:
- Comprehensive checklist detailing 20+ key controls across FI, MM, and SD modules.
- Quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N utilities.
Summary and Next Steps
Requirements
- Proficiency in fundamental auditing standards
- Practical experience utilizing SAP environments
- Knowledge of established compliance and control protocols
Target Audience
- Audit professionals
- Internal controls experts
- SAP security advisors
- Compliance managers
Testimonials (2)
In question and answer section, we can ask many cases and Mr. Oki is great to make us understand the solution of our issues.
Verified Client
Course - Mastering On-Premise SAP Fiori Development
It was straight to the point and more practical