Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Session 1 (4h)
Module 1 – R/3 Fundamentals for Auditors (2h)
- Core architecture (ABAP stack, SAP GUI, client concept).
- Key distinctions from legacy systems (modular design: FI, MM, SD).
- Classic transactions and navigation tailored for audit purposes.
Module 2 – Access, Roles, and Essential SoD (2h)
- User management and authorizations using PFCG, SU01, SUIM, SU53, and SU24.
- Role design and common functions relevant to audits.
- Overview of the basic SoD matrix and typical findings (e.g., invoice creation and approval within the same role).
Session 2 (4h)
Module 3 – Security Logs and Traces (3h)
- Security Audit Log (SM19/SM20): activation, filters, and reporting.
- STAD and ST03N: analyzing usage statistics, sessions, and workload.
- Best practices for retaining and exporting evidence.
Module 4 – Configuration Changes and Sensitive Data (1h)
- SCU3 (change documents) and SCC4 (client settings).
- Identifying and monitoring critical system parameters (RZ10/RZ11).
Session 3 (4h)
Module 5 – Process Controls (FI/MM/SD) in R/3 (4h)
- FI: tolerances, OB52 (posting periods), and journal entry approvals.
- MM: release strategies, purchase order limits, and single supplier controls.
- SD: credit limits, pricing changes, and conditions monitoring.
- Audit sampling techniques for process testing.
Session 4 (4h)
Module 6 – Comprehensive Laboratory + Reporting (3h)
- Reviewing roles and authorizations for a critical user.
- Tracing operations (purchase/sale) and obtaining audit evidence (SM20/SCU3).
- Documenting findings with screenshots and exports.
- Preparing working papers and ensuring traceability.
Module 7 – Closure and Action Plan (1h)
- Internal control checklist for R/3.
- Prioritizing findings and recommendations.
Deliverables:
- Checklist of 20+ controls (FI/MM/SD).
- Quick guide to SM19/SM20, SUIM, SCU3, and STAD/ST03N.
Summary and Next Steps
Requirements
- A solid understanding of basic auditing principles
- Experience with SAP systems
- Familiarity with compliance and control frameworks
Target Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
16 Hours
Testimonials (2)
It was straight to the point and more practical
Lungelo Ndlela - SNG Grant Thornton
Course - SAP S/4 Hana (S/4Hana)
The interaction between the team and sharing their experience with us
Brenda Toral - Michelin Mexico Services
Course - SAP S/4HANA Overview (S4H00)
Machine Translated