Course Outline
Session 1 (4 hours)
Module 1 – S/4HANA Fundamentals for Auditors (2 hours)
- Core architecture components (ABAP, Fiori, catalogs, and roles).
-
Key differences from ECC:
- Business Partner functionality.
- Universal Journal (ACDOCA).
- Flexible Workflows.
- Current landscape of Audit Information System (AIS) locations, including transactions and their Fiori equivalents.
Module 2 – Access, Roles, and Essential SoD (2 hours)
- User management, PFCG, SUIM, SU53, and SU24 (authorizations via transaction codes).
- Fiori catalogs and role structures (app-id, catalog, and space).
- Basic SoD matrices and common findings (e.g., combined creation and release authorities in a single role).
Session 2 (4 hours)
Module 3 – Security Logs and Traces (3 hours)
- Security Audit Log (SM19/SM20): activation, filtering, and interpretation.
- STAD/ST03N: analyzing usage statistics, sessions, and peak activity.
- Read Access Logging (RAL): conceptual understanding and application scenarios.
- Best practices for retaining and exporting audit evidence.
Module 4 – Configuration Changes and Sensitive Data (1 hour)
- Change documents (SCU3) and change policies (SCC4).
- Critical parameters (RZ10/RZ11): review and evidence collection.
Session 3 (4 hours)
Module 5 – Process Controls (FI/MM/SD) in S/4 (4 hours)
- FI: Tolerance limits, OB52 (posting periods), entry segregation, and journal approval workflows.
- MM: Release strategies, limit settings, single supplier rules, and condition changes.
- SD: Credit limits (FSCM Credit Management) and price/condition modifications.
- BP: Controls on creation/exchange and fiscal/banking data sensitivity.
- Risk-based sampling and selection methodologies.
Session 4 (4 hours)
Module 6 – Comprehensive Laboratory + Reporting (3 hours)
- Simulating role and access elevation for a critical user profile.
- Tracing business operations (buy/sell) and capturing evidence via SM20/SCU3.
- Documenting findings with screenshots and data exports.
- Drafting working papers and ensuring full traceability.
Module 7 – Closure and Action Planning (1 hour)
- Internal control checklist tailored for S/4 environments.
- Prioritizing audit findings and formulating recommendations.
Course Deliverables:
- A comprehensive checklist covering 20+ controls across FI/MM/SD/BP.
- Quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N.
Requirements
- Foundational knowledge of auditing principles
- Prior exposure to SAP systems
- Familiarity with compliance standards and control frameworks
Target Audience
- Internal and external auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
Testimonials (2)
It was straight to the point and more practical
Lungelo Ndlela - SNG Grant Thornton
Course - SAP S/4 Hana (S/4Hana)
His calm and collected voice even though at points he was frustrated with the system, but kept his cool…