Kursplan
Session 1 (4h)
Module 1 – R/3 Fundamentals for Auditors (2h)
- Basic architecture (ABAP stack, SAP GUI, client concept).
- Key differences from legacy systems (modular design: FI, MM, SD).
- Classic transactions and navigation for audit purposes.
Module 2 – Access, Roles, and Essential SoD (2h)
- User management and authorizations with PFCG, SU01, SUIM, SU53, SU24.
- Role design and common audit-relevant functions.
- Basic SoD matrix and typical findings (e.g., invoice creation and approval in the same role).
Session 2 (4h)
Module 3 – Security Logs and Traces (3h)
- Security Audit Log (SM19/SM20): activation, filters, and reporting.
- STAD and ST03N: usage statistics, sessions, and workload analysis.
- Good practices for evidence retention and export.
Module 4 – Configuration Changes and Sensitive Data (1h)
- SCU3 (change documents) and SCC4 (client settings).
- Critical system parameters (RZ10/RZ11): identification and monitoring.
Session 3 (4h)
Module 5 – Process Controls (FI/MM/SD) in R/3 (4h)
- FI: tolerances, OB52 (posting periods), journal entry approvals.
- MM: release strategies, purchase order limits, single supplier controls.
- SD: credit limits, pricing changes, conditions monitoring.
- Audit sampling techniques for process testing.
Session 4 (4h)
Module 6 – Comprehensive Laboratory + Reporting (3h)
- Review roles and authorizations for a critical user.
- Trace operations (purchase/sale) and obtain audit evidence (SM20/SCU3).
- Document findings with screenshots and exports.
- Preparation of working papers and traceability.
Module 7 – Closure and Action Plan (1h)
- Internal control checklist in R/3.
- Prioritization of findings and recommendations.
Deliverables:
- Checklist of 20+ controls (FI/MM/SD).
- Quick guide to SM19/SM20, SUIM, SCU3, STAD/ST03N.
Summary and Next Steps
Krav
- An understanding of basic auditing principles
- Experience with SAP systems
- Familiarity with compliance and control frameworks
Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
Referanser (4)
Lærer knolage
Collin Sampson
Kurs - SAP S/4HANA Overview (S4H00)
Machine Translated
Jeg likte det faktum at treneren var veldig fleksibel og tilbød informasjon om emner som ikke var inkludert i det innledende materialet. Jeg likte erfaringen hans i andre prosjekter, og tipsene og triksene resulterte fra denne erfaringen. Treningen var interaktiv og selv om øvelsene var forhåndsdefinerte kunne vi ta øvelsen i en annen retning enn tidligere definert.
Maria-Cristina Socol - NTT DATA Romania S.A.
Kurs - SAP S/4 Hana (S/4Hana)
Machine Translated
We have learnt so many things that we didn't know before.
Lebogang Kgosiesele - Lucara Botswana
Kurs - SAP S/4 HANA PP (Production Planning)
Ayman was a very good trainer. He explained our doubts and was very easy to understand. He gave satisfactory answer to all questions we raised.