Course Outline
Session 1 (4h)
Module 1 – S/4HANA Fundamentals for Auditors (2h)
- Core architecture components (ABAP, Fiori, catalogs, and roles).
-
Significant differences from ECC:
- Business Partner concept.
- Universal Journal (ACDOCA).
- Flexible workflows.
- Current AIS location: transaction codes and their Fiori equivalents.
Module 2 – Access Management, Roles, and Essential SoD (2h)
- Management of users, PFCG, SUIM, SU53, and SU24 (authorizations by transaction code).
- Fiori catalogs and role assignments (app-id, catalog, space).
- Basic SoD matrix construction and common findings (e.g., combining creation and release in one role).
Session 2 (4h)
Module 3 – Security Logs and Tracing (3h)
- Security Audit Log (SM19/SM20): activation, filtering, and analysis.
- STAD/ST03N: analyzing usage statistics, sessions, and peak loads.
- Read Access Logging (RAL): concepts and applicable scenarios.
- Best practices for evidence retention and data export.
Module 4 – Configuration Changes and Sensitive Data (1h)
- Reviewing change documents (SCU3) and change policies (SCC4).
- Assessing critical parameters (RZ10/RZ11): interpretation and evidence collection.
Session 3 (4h)
Module 5 – Process Controls (FI/MM/SD) in S/4 (4h)
- FI: Tolerances, posting periods (OB52), entry segregation, and journal approvals (workflows).
- MM: Release strategies, limits, single source sourcing, and condition changes.
- SD: Credit limits (FSCM Credit Management) and price/condition modifications.
- BP: Controls on creation/maintenance and fiscal/banking data sensitivity.
- Risk-based sampling and selection methodologies.
Session 4 (4h)
Module 6 – Comprehensive Lab + Reporting (3h)
- Elevating the roles and access rights of a critical user for testing purposes.
- Tracing specific operations (purchase/sale) and gathering evidence (SM20/SCU3).
- Recording findings along with relevant screenshots and exports.
- Preparing working papers and ensuring full traceability.
Module 7 – Conclusion and Action Plan (1h)
- Internal control checklist specific to S/4.
- Prioritizing findings and formulating recommendations.
Course Deliverables:
- A checklist containing 20+ controls for FI/MM/SD/BP.
- A quick reference guide for SM19/SM20, SUIM, SCU3, and STAD/ST03N.
Requirements
- A solid understanding of fundamental auditing principles
- Prior experience working with SAP systems
- Familiarity with established compliance and control frameworks
Intended Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
Testimonials (2)
It was straight to the point and more practical
Lungelo Ndlela - SNG Grant Thornton
Course - SAP S/4 Hana (S/4Hana)
His calm and collected voice even though at points he was frustrated with the system, but kept his cool…