Get in Touch

Course Outline

R/3 Essentials for Auditors

  • Core architecture components, including the ABAP stack, SAP GUI, and the client concept.
  • Distinct features compared to legacy systems, highlighting the modular design (FI, MM, SD).
  • Standard transactions and navigation methods applicable to audit activities.

Access Control, Roles, and Core SoD

  • User management and authorization handling via PFCG, SU01, SUIM, SU53, and SU24.
  • Role structuring and frequently encountered audit-critical functions.
  • Basic SoD matrices and common issues, such as combining invoice creation and approval within a single role.

Security Logs and System Traces

  • Managing the Security Audit Log (SM19/SM20): enabling, filtering, and reporting.
  • Utilizing STAD and ST03N for usage metrics, session analysis, and workload evaluation.
  • Best practices for maintaining and exporting evidence.

Configuration Updates and Sensitive Information

  • Monitoring change documents via SCU3 and client settings via SCC4.
  • Identifying and tracking critical system parameters using RZ10/RZ11.

Process Controls in R/3 (FI/MM/SD)

  • FI module: tolerances, OB52 (posting periods), and journal entry authorization workflows.
  • MM module: release strategies, purchase order thresholds, and single-supplier oversight.
  • SD module: credit limits, price modifications, and condition monitoring.
  • Sampling methods applied to process testing.

Comprehensive Laboratory and Reporting

  • Inspecting roles and authorizations for high-risk users.
  • Tracing transactions (purchases/sales) and collecting audit proof via SM20/SCU3.
  • Recording observations with visual captures and data exports.
  • Drafting working papers and ensuring traceability.

Conclusion and Action Plan

  • Reviewing the internal control checklist within R/3.
  • Prioritizing identified findings and formulating recommendations.

Key Deliverables

  • A checklist containing over 20 controls for FI, MM, and SD.
  • A concise guide to using SM19/SM20, SUIM, SCU3, and STAD/ST03N.

Requirements

  • Foundational knowledge of auditing principles
  • Professional experience with SAP systems
  • Awareness of compliance and control frameworks

Target Audience

  • Auditors
  • Internal control experts
  • SAP security consultants
  • Compliance officers
 16 Hours

Number of participants


Price per participant

Testimonials (2)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories