Programa do Curso
Session 1 (4h)
Module 1 – R/3 Fundamentals for Auditors (2h)
- Basic architecture (ABAP stack, SAP GUI, client concept).
- Key differences from legacy systems (modular design: FI, MM, SD).
- Classic transactions and navigation for audit purposes.
Module 2 – Access, Roles, and Essential SoD (2h)
- User management and authorizations with PFCG, SU01, SUIM, SU53, SU24.
- Role design and common audit-relevant functions.
- Basic SoD matrix and typical findings (e.g., invoice creation and approval in the same role).
Session 2 (4h)
Module 3 – Security Logs and Traces (3h)
- Security Audit Log (SM19/SM20): activation, filters, and reporting.
- STAD and ST03N: usage statistics, sessions, and workload analysis.
- Good practices for evidence retention and export.
Module 4 – Configuration Changes and Sensitive Data (1h)
- SCU3 (change documents) and SCC4 (client settings).
- Critical system parameters (RZ10/RZ11): identification and monitoring.
Session 3 (4h)
Module 5 – Process Controls (FI/MM/SD) in R/3 (4h)
- FI: tolerances, OB52 (posting periods), journal entry approvals.
- MM: release strategies, purchase order limits, single supplier controls.
- SD: credit limits, pricing changes, conditions monitoring.
- Audit sampling techniques for process testing.
Session 4 (4h)
Module 6 – Comprehensive Laboratory + Reporting (3h)
- Review roles and authorizations for a critical user.
- Trace operations (purchase/sale) and obtain audit evidence (SM20/SCU3).
- Document findings with screenshots and exports.
- Preparation of working papers and traceability.
Module 7 – Closure and Action Plan (1h)
- Internal control checklist in R/3.
- Prioritization of findings and recommendations.
Deliverables:
- Checklist of 20+ controls (FI/MM/SD).
- Quick guide to SM19/SM20, SUIM, SCU3, STAD/ST03N.
Summary and Next Steps
Requisitos
- An understanding of basic auditing principles
- Experience with SAP systems
- Familiarity with compliance and control frameworks
Audience
- Auditors
- Internal control specialists
- SAP security consultants
- Compliance officers
Declaração de Clientes (4)
Conhecimento do professor
Collin Sampson
Curso - SAP S/4HANA Overview (S4H00)
Máquina Traduzida
Gostei do facto de o formador ser muito flexível e oferecer informações sobre assuntos que não estavam incluídos no material inicial. Gostei da sua experiência noutros projectos e das dicas e truques resultantes dessa experiência. A formação foi interactiva e, apesar de os exercícios estarem pré-definidos, podíamos levar o exercício noutra direção que não a previamente definida.
Maria-Cristina Socol - NTT DATA Romania S.A.
Curso - SAP S/4 Hana (S/4Hana)
Máquina Traduzida
Nós aprendemos muitas coisas que não sabíamos antes.
Lebogang Kgosiesele - Lucara Botswana
Curso - SAP S/4 HANA PP (Production Planning)
Máquina Traduzida
Ayman foi um excelente treinador. Ele esclareceu nossas dúvidas e foi muito fácil de entender. Deu respostas satisfatórias a todas as perguntas que fizemos.
Anna Bytnar - ABB
Curso - SAP S/4 HANA SD (Sales and Distribution)
Máquina Traduzida