About - SAP SOX Control Baselines

Baseline SAP-centric business process and IT control frameworks for building SOX programs.

About the Author

Brendan Deery

LinkedIn Profile

Senior Manager, IT Internal Audit

Internal Audit and SOX leader with 16+ years of Big 4 and industry experience in enterprise environments centered on SAP and Workday. CA/CPA, CISA, CISSP, and AAISM with a track record of building SOX programs, designing ITGCs and automated controls, and advising management on ERP security, change management, and financial reporting risk across integrated system landscapes. Experience includes Big 4 client work, SAP S/4HANA and ECC implementations, Workday Financials and HCM deployments, and in-house audit leadership at publicly listed companies typically in environments where SAP S/4HANA sits at the core and connects to a broader set of applications.

These baselines reflect lessons learned from dozens of SAP-centric control design and testing engagements, acquisitions, and system implementations. They're purpose-built for organizations running SAP S/4HANA, helping you design and test SOX controls that fit your specific environment and risk profile.

Certifications

  • CA/CPA - Chartered Accountant
  • CISA - Certified Information Systems Auditor
  • CISSP - Certified Information Systems Security Professional
  • AAISM - Advanced in AI Security Management
  • CIA - Certified Internal Auditor

Key Experience

  • SAP S/4HANA & ECC expertise
  • SOX program design & execution
  • ITGC & ITAC testing
  • Control design & remediation
  • Cybersecurity & technology risk reviews
  • Data analytics supporting audit (Alteryx, SQL, Python)
  • Big 4 & industry audit leadership

Explore SOX Control Baselines

SOX Control Baselines for SAP Environments

This site was built to share a practical baseline, a set of SAP-centric business process controls and IT General Controls (ITGCs) around which organizations can build and mature their SOX programs.

The resources here cover key SAP business processes (Procure to Pay, Order to Cash, Record to Report, Acquire to Retire and Inventory) with mapped SOX controls, as well as core ITGCs (access management, change control, computer operations) that apply across SAP environments. Organizations can use these as a starting point, customize them to their risk profile and process design, and build a more mature control environment from there.

What's Included

SAP Business Process Controls

Baseline control matrices for key SAP processes (Procure to Pay, Order to Cash, Record to Report,Acquire to Retire and Inventory). Each includes business risks, control objectives, and control designs mapped to SOX compliance requirements.

IT General Controls (ITGCs)

Core ITGC frameworks for SAP access management, change control, batch processing, and backup management.

Control Mapping & Matrices

Interactive workflow dashboards showing SAP business process flows and how controls map to SOX requirements. Click on any process node to filter and explore related controls, test procedures, and audit evidence. Workflows visualize both primary processes and related controls in an intuitive, click-driven interface.

How to Use These Baselines

These frameworks are starting points, not final solutions. Use them to:

  • Assess current state: Compare your existing controls against the baseline to identify gaps.
  • Design controls: Adapt control designs to your business processes, system configurations, and risk profile.
  • Plan testing: Use the control matrices to scope and execute SOX testing programs.
  • Maintain controls: Build on these frameworks as your SAP environment evolves and your organization matures.