Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Session 1 (4 hours)
Module 1 – R/3 Fundamentals for Auditors (2 hours)
- Core architecture (ABAP stack, SAP GUI, client concept).
- Key distinctions from legacy systems (modular design: FI, MM, SD).
- Classic transactions and navigation tailored for audit purposes.
Module 2 – Access, Roles, and Essential SoD (2 hours)
- User management and authorizations using PFCG, SU01, SUIM, SU53, and SU24.
- Role design and common audit-relevant functions.
- Introduction to the SoD matrix and typical findings (e.g., invoice creation and approval assigned to the same role).
Session 2 (4 hours)
Module 3 – Security Logs and Traces (3 hours)
- Security Audit Log (SM19/SM20): activation, filters, and reporting.
- STAD and ST03N: utilization statistics, sessions, and workload analysis.
- Best practices for evidence retention and export.
Module 4 – Configuration Changes and Sensitive Data (1 hour)
- SCU3 (change documents) and SCC4 (client settings).
- Critical system parameters (RZ10/RZ11): identification and monitoring.
Session 3 (4 hours)
Module 5 – Process Controls (FI/MM/SD) in R/3 (4 hours)
- FI: tolerances, OB52 (posting periods), and journal entry approvals.
- MM: release strategies, purchase order limits, and single supplier controls.
- SD: credit limits, pricing changes, and condition monitoring.
- Audit sampling techniques for process testing.
Session 4 (4 hours)
Module 6 – Comprehensive Laboratory + Reporting (3 hours)
- Review roles and authorizations for critical users.
- Trace operations (purchase/sale) and gather audit evidence (SM20/SCU3).
- Document findings using screenshots and exports.
- Preparation of working papers and ensuring traceability.
Module 7 – Closure and Action Plan (1 hour)
- Internal control checklist for R/3.
- Prioritization of findings and recommendations.
Deliverables:
- Checklist of 20+ controls (FI/MM/SD).
- Quick guide to SM19/SM20, SUIM, SCU3, and STAD/ST03N.
Summary and Next Steps
Requirements
- Fundamental understanding of auditing principles
- Hands-on experience with SAP systems
- Familiarity with compliance and control frameworks
Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
16 Hours
Testimonials (2)
It was straight to the point and more practical
Lungelo Ndlela - SNG Grant Thornton
Course - SAP S/4 Hana (S/4Hana)
His calm and collected voice even though at points he was frustrated with the system, but kept his cool…