Get in Touch

Course Outline

Session 1 (4 hours)

Module 1 – R/3 Fundamentals for Auditors (2 hours)

  • System architecture overview, including the ABAP stack, SAP GUI interface, and client management concepts.
  • Distinctions between legacy environments and S/4HANA, emphasizing modular functional areas such as Financials (FI), Materials Management (MM), and Sales and Distribution (SD).
  • Navigating standard transactions to support audit objectives.

Module 2 – Access Control, Roles, and Segregation of Duties (2 hours)

  • User administration and authorization management using PFCG, SU01, SUIM, SU53, and SU24 tools.
  • Role design principles and identification of audit-critical functions within R/3 for government operations.
  • Overview of the Segregation of Duties (SoD) matrix, including common compliance findings such as dual authorization for invoice creation and approval within a single role.

Session 2 (4 hours)

Module 3 – Security Logging and Trace Analysis (3 hours)

  • Security Audit Log configuration via SM19/SM20, including filter settings and reporting capabilities.
  • Utilization of STAD and ST03N for usage statistics, session monitoring, and workload analysis.
  • Best practices for retaining audit evidence and exporting logs for review.

Module 4 – Configuration Changes and Sensitive Data Management (1 hour)

  • Review of change documents via SCU3 and client-level configurations using SCC4.
  • Identification and monitoring of critical system parameters through RZ10/RZ11.

Session 3 (4 hours)

Module 5 – Process Controls in FI/MM/SD within R/3 (4 hours)

  • Financials (FI): Management of tolerances, posting periods (OB52), and journal entry approval workflows.
  • Materials Management (MM): Implementation of release strategies, purchase order thresholds, and supplier-specific controls.
  • Sales and Distribution (SD): Oversight of credit limits, pricing modifications, and condition monitoring.
  • Audit sampling methodologies for process validation.

Session 4 (4 hours)

Module 6 – Comprehensive Laboratory Exercise and Reporting (3 hours)

  • Evaluation of roles and authorizations assigned to critical user accounts.
  • Tracing transactional operations (procurement and sales) and collecting audit evidence via SM20 and SCU3 for government compliance.
  • Documentation of findings using screenshots and system exports.
  • Preparation of working papers and establishment of traceability.

Module 7 – Program Closure and Action Plan (1 hour)

  • Application of an internal control checklist specific to R/3.
  • Prioritization of identified findings and formulation of corrective recommendations.

Deliverables:

  • Comprehensive checklist detailing 20+ key controls across FI, MM, and SD modules.
  • Quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N utilities.

Summary and Next Steps

Requirements

  • Proficiency in fundamental auditing standards
  • Practical experience utilizing SAP environments
  • Knowledge of established compliance and control protocols

Target Audience

  • Audit professionals
  • Internal controls experts
  • SAP security advisors
  • Compliance managers
 16 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories