|
A2R-01
|
Acquire to Retire |
Asset Master Data |
Unauthorized personnel could create fraudulent asset records or modify asset master parameters (such as useful lives, cost centers, or capitalization dates), leading to misstated asset values and improper financial reporting |
Management enforces restrictions on fixed asset master data by assigning transaction-level authorizations (such as AS01 and AS02 for creation and modification) exclusively to authorized accounting personnel |
|
A2R-02
|
Acquire to Retire |
Internal Order |
Unauthorized employees could open or manipulate capital internal orders, leading to misallocated capital expenditures, improper capitalization of operating expenses, or delayed asset depreciation. |
Management enforces access restrictions within SAP S/4HANA to ensure that the creation, modification, and settlement of internal orders dedicated to Construction in Progress (restricted to specific capital order types) are limited strictly to authorized project accounting and finance personnel via transaction codes KO01, KO02, and KO04. |
|
A2R-03
|
Acquire to Retire |
Depreciation |
Incorrect depreciation parameters or unapproved charts of depreciation could be assigned to asset classes, leading to misstated depreciation expense and inaccurate net book values on the financial statements |
SAP S/4HANA is configured to automatically calculate depreciation using system-defined parameters. The calculation logic is strictly governed by the approved Chart of Depreciation, Depreciation Keys, Asset Classes, and Useful Lives assigned within the system, ensuring alignment with corporate accounting policies. |
|
A2R-04
|
Acquire to Retire |
Reporting |
Fixed asset acquisitions, accumulated depreciation, or depreciation expenses could be posted to incorrect general ledger accounts, leading to misstated asset valuations and operating expenses. |
SAP S/4HANA utilizes automated account determination logic to ensure fixed asset general ledger postings automatically route to designated balance sheet and P&L accounts based on asset class selection. |
|
A2R-05
|
Acquire to Retire |
Asset Master Data |
Risk of material misstatement in the Fixed Assets financial statement line items (including Asset Acquisition and Accumulated Depreciation) due to unauthorized, erroneous, or direct manual General Ledger journal entries bypassing the sub-ledger, leading to a lack of reconciliation between the Asset Accounting sub-ledger and the General Ledge |
Fixed asset balance sheet accounts (including asset acquisition and accumulated depreciation) are configured as reconciliation accounts in SAP S/4HANA to prevent direct manual journal entries in the General Ledger. |
|
INV-01
|
Inventory |
Inventory |
Unauthorized creation or modification of material costs in SAP S/4HANA could lead to inaccurate inventory valuation, misstatement of cost of goods sold (COGS), and material errors in financial reporting. |
Access to transaction codes and authorization objects permitted to create or update material costs in SAP S/4HANA is restricted to authorized personnel |
|
INV-02
|
Inventory |
Inventory |
Errors in the release or calculation of new standard costs may result in a material misstatement of inventory valuation and financial results due to improper inventory revaluation |
Upon the release of a new standard cost estimate, the system automatically revalues existing on-hand inventory across all inventory categories (Raw Materials, WIP, Semi-Finished Goods, Finished Goods, and Transit) and records the resulting inventory revaluation adjustment to the designated balance sheet and gain/loss accounts. |
|
INV-03
|
Inventory |
Inventory |
Production variances may be inaccurate, incomplete, or invalid, leading to material misstatements in inventory valuation and cost of goods sold (COGS) if they are not reviewed and resolved by management prior to order settlement. |
On a monthly basis, prior to order settlement, production variances are reviewed by management to facilitate completeness, accuracy, and validity of the recorded production activity. |
|
INV-04
|
Inventory |
Inventory |
Inaccurate calculation or improper cutoff of production order WIP and variances may result in a material misstatement of inventory valuation and cost of goods sold (COGS). |
The system automatically calculates Work in Process (WIP) for open production orders at period-end. For closed or technically complete orders, the system calculates variances and posts them to the appropriate financial statement lines during settlement. |
|
INV-05
|
Inventory |
Inventory |
Inaccurate inventory valuation and financial statement misstatement due to the failure to perform timely physical inventory cycle counts for high-value or high-velocity materials, or unauthorized modification of ABC cycle counting classification parameters in SAP S/4HANA |
Access to assign ABC cycle count indicator or "CC Fixed" flags in the material master via tcodes such as MIBC or MM02 is restricted. |
|
INV-06
|
Inventory |
Inventory |
Inventory discrepancies may go undetected or uncorrected, leading to misstated inventory balances if management fails to periodically review cycle count accuracy metrics against established policy thresholds. |
Management periodically reviews completed versus scheduled cycle count documents in SAP to ensure all assigned material locations have been fully counted per the established schedule |
|
INV-07
|
Inventory |
Inventory |
Inaccurate inventory valuation and financial statement misstatement due to the failure to perform timely physical inventory cycle counts for high-value or high-velocity materials, or unauthorized modification of ABC cycle counting classification parameters in SAP S/4HANA |
ABC cycle count indicators are configured in SAP to specify the frequency of inventory counts for materials depending on the assignment of A, B, or C indicators |
|
INV-08
|
Inventory |
Inventory |
Inventory discrepancies may go undetected or uncorrected, leading to misstated inventory balances if management fails to periodically review cycle count accuracy metrics against established policy thresholds. |
Management performs periodic reviews of cycle count inventory accuracy metrics to verify that they meet the thresholds in the policy. |
|
INV-09
|
Inventory |
Inventory |
Inventory reserves for slow-moving and obsolete items could be materially misstated or inaccurate if calculations and assumptions are not independently reviewed and approved by management prior to posting journal entries to SAP. Without this review, errors, unsupported assumptions, or fraudulent adjustments could be posted without detection, resulting in the understatement or overstatement of inventory valuation and a misstatement of the balance sheet. |
On a quarterly basis, the slow moving and obsolete reserve calculations and assumptions are reviewed and approved by management for accuracy and validity prior to the manual journal entry posting in SAP |
|
OTC-01
|
Order to Cash |
Customer Master Data |
One person acting alone could alter customer data or direct remittances to fraudulent bank accounts without oversight |
Changes to key fields in the customer master table (such as bank details, tax indicators, and address data) take two people to complete; one to enter, and a second to approve. |
|
OTC-02
|
Order to Cash |
Credit master data |
Unauthorized employees could alter customer credit limits or risk categories without proper review, leading to excessive credit exposure, unapproved credit extensions, and potential bad debt write-offs. |
Access to modify credit limit and risk category fields in the customer master record is restricted to authorized credit management personnel. |
|
OTC-03
|
Order to Cash |
Pricing Master Data |
Unauthorized employees could alter product prices or discounts without proper review, leading to incorrect customer billings, revenue leakage, or unauthorized sales concessions. |
Access to create, change, or delete sales pricing conditions is restricted to authorized pricing or finance personnel. |
|
OTC-04
|
Order to Cash |
Sales Order |
Sales orders could be fulfilled and shipped to customers whose total credit exposure exceeds their authorized limit, leading to uncollectible accounts receivable and financial loss. |
SAP S/4HANA automatically evaluates a customer's total credit exposure against their assigned credit limit during sales order processing, blocking orders that cause the credit exposure to exceed the limit |
|
OTC-05
|
Order to Cash |
Sales Order |
Unauthorized employees could manually release credit-blocked sales orders without proper financial review, leading to shipments to high-risk or over-limit customers and potential bad debt write-offs. |
Access to release sales orders from credit blocks using SAP S/4HANA credit management tools is restricted to authorized credit management personnel. |
|
OTC-06
|
Order to Cash |
Sales Order |
Unauthorized manual price overrides or excessive discounts could go undetected, resulting in compressed profit margins, unapproved concessions, and lost revenue. |
Management performs a periodic review of sales order gross margins to identify and investigate transactions with abnormal discounts, manual price overrides, or low-margin profiles. |
|
OTC-07
|
Order to Cash |
Delivery |
Manual re-entry or discrepancies between sales orders and deliveries could result in shipping incorrect items, wrong quantities, or delivering to the wrong customer, leading to customer disputes and inventory errors |
SAP S/4HANA automatically copies key elements of the sales order such as the ship-to party, material, and quantity to the delivery document (for picking) completely and accurately. |
|
OTC-08
|
Order to Cash |
Delivery |
Cost of goods sold could be posted incorrectly or omitted during inventory fulfillment, leading to misstated operational expenses and inventory balances on the financial statements. |
SAP S/4HANA automatically posts the cost of goods sold to the appropriate general ledger accounts upon post goods issue (PGI), utilizing automated account determination (OBYC) and configured cost component splits to ensure accurate financial reporting. |
|
OTC-09
|
Order to Cash |
Billing |
Discrepancies between what was shipped and what was billed could result in inaccurate customer invoices, under-billed revenue, or billing customers for unfulfilled items. |
SAP S/4HANA automatically copies key data elements from the sales order and delivery document (such as material, delivery quantity, price, and sold-to party) directly into the billing document upon creation after Post Goods Issue (PGI), ensuring complete and accurate customer invoicing without manual re-entry. |
|
OTC-10
|
Order to Cash |
Billing |
If trade receivable G/L accounts are not properly configured as reconciliation accounts in SAP, users could post direct manual journal entries to the control account. This would cause a discrepancy between the General Ledger balance and the Customer Subledger, potentially leading to material misstatements in financial reporting, delayed detection of billing errors, or an increased risk of undetected fraudulent adjustments going unmonitored by management. |
Trade receivable accounts are configured as reconciliation accounts in SAP S/4HANA to prevent direct manual journal entries in the General Ledger. The reconciliation account is mapped to the customer master financial view (KNB1-AKONT), ensuring all transactional postings automatically update the customer subledger and aggregate to the General Ledger control account. |
|
OTC-11
|
Order to Cash |
Billing |
If eligible deliveries are not processed accurately or completely into invoices and G/L postings through the automated batch job, revenue and trade receivables could be misstated (incomplete, inaccurate, or recorded in the wrong period). This could lead to material misstatements in financial reports and undetected discrepancies between shipping logs and accounting records. |
The system automatically processes eligible unblocked deliveries via a scheduled nightly batch job to generate customer invoices, concurrently creating automated general ledger postings for trade accounts receivable and product revenue |
|
OTC-12
|
Order to Cash |
Accounts Receivable - Other |
Uncollectible customer balances could go unidentified and unreserved, leading to an understated allowance for doubtful accounts and materially misstated financial statements. |
Management performs a periodic review of the Accounts Receivable aging report to assess customer account collectability, identify overdue balances, and evaluate the adequacy of the allowance for doubtful accounts |
|
P2P-01
|
Procure to Pay |
Vendor |
One person acting alone could change vendor payment details without oversight |
Changes to key fields in the vendor table take two people to complete; one to enter, and a second to approve. |
|
P2P-02
|
Procure to Pay |
Purchase Order |
Purchases could be processed using incorrect matching rules, such as paying for inventory without verifying a goods receipt, leading to unverified disbursements or incorrect payments |
SAP automatically enforces matching rules based on how an item is purchased (such as standard warehouse inventory, internal transfers, or drop shipments) governed by the item category configuration. For standard inventory purchases into the warehouse, the system requires a 3-way match between the purchase order, goods receipt, and vendor invoice before payment. For other purchase types, the system applies the appropriate alternative match, such as verifying only the purchase order and goods receipt for internal transfers |
|
P2P-03
|
Procure to Pay |
Purchase Order |
Unauthorized or inaccurate purchase orders could be placed and fulfilled without proper management review and approval. |
SAP S/4HANA automatically blocks new and changed purchase orders based on their type and dollar amount, requiring someone other than the creator to approve them before they can be processed. |
|
P2P-04
|
Procure to Pay |
Good Receipt |
Received inventory might not get recorded as a liability, causing accounts payable to be understated. |
SAP S/4HANA automatically posts the accrual to the Goods Receipt/Invoice Receipt (GR/IR) clearing account upon the successful posting of an inventory goods receipt, ensuring the timely recording of liabilities. |
|
P2P-05
|
Procure to Pay |
Good Receipt |
The business could accept and inventory unauthorized excess quantities from a vendor, resulting in inventory overstock, inaccurate physical counts, and potential financial over-obligation before an invoice is even processed. |
SAP enforces delivery limits during goods receipt processing by comparing received quantities against Purchase Order quantities, using tolerance thresholds defaulted via Purchasing Value Keys or Purchasing Info Records. If a delivery exceeds the configured acceptance limits, the system automatically blocks the goods receipt posting, preventing inventory acceptance for unapproved quantities |
|
P2P-06
|
Procure to Pay |
Invoice receipt |
The company could accidentally pay for goods or services that were never actually received, leading to financial loss. |
SAP automatically compares vendor invoice quantities to goods receipt quantities using Tolerance Key DQ. If a variance exceeds the configured threshold, the system automatically blocks the invoice from payment to prevent disbursement for unreceived goods. Blocked invoices require manual review and management approval before release. |
|
P2P-07
|
Procure to Pay |
Invoice receipt |
The company could pay a higher price than what was originally agreed upon and approved in the purchase order, leading to overpayment. |
SAP compares invoice prices against purchase order prices using Tolerance Key PP. If a price variance exceeds the configured threshold, the system automatically blocks the invoice from payment to prevent overbilling. Blocked invoices require manual review and management approval before release. |
|
P2P-08
|
Procure to Pay |
Invoice receipt |
Blocked invoices could remain unresolved indefinitely, leading to delayed vendor payments, strained vendor relationships, or unauthorized manual overrides of legitimate blocks. |
Management reviews the blocked invoice report via transaction MRBR detailing invoices held for price (PP) and/or quantity (DQ) variances on a periodic basis to investigate and resolve discrepancies in a timely manner. |
|
P2P-09
|
Procure to Pay |
Invoice receipt |
The company could accidentally process and pay the same PO invoice twice due to duplicate submissions or processing errors, resulting in unauthorized financial outflows. |
SAP automatically checks for duplicate vendor invoices during PO invoice entry. If a new invoice matches key details of a previously posted bill (such as the vendor, invoice date, reference number, company code, and amount), the system triggers an error message that blocks the duplicate posting. |
|
P2P-10
|
Procure to Pay |
Accounts Payable - Other |
Unresolved differences between what was ordered, received, and billed could accumulate over time, leading to misstated financial records or incorrect expense and inventory balances. |
Management performs a monthly review of the GR/IR clearing account report to identify, investigate, and resolve aged or unbalanced quantity and value differences between goods receipts and vendor invoices. |
|
P2P-11
|
Procure to Pay |
Non-PO Invoice |
Unauthorized or fraudulent non-PO invoices could be posted and paid without proper management review and approval, resulting in unapproved expenses or financial loss. |
Non-PO invoices received through the OpenText Vendor Invoice Management (VIM) add-on to SAP S/4HANA are routed for appropriate business approvals before posting in the financial system. |
|
P2P-12
|
Procure to Pay |
Non-PO Invoice |
Users could retain excessive or unauthorized approval limits, allowing fraudulent or unapproved non-PO expenses to be processed and paid without proper oversight. |
Management periodically reviews the OpenText VIM authorization matrix to verify that users are assigned appropriate approval limits for non-PO invoices. |
|
P2P-13
|
Procure to Pay |
Non-PO Invoice |
The company could accidentally process and pay the same non-PO vendor invoice twice due to duplicate submissions or processing errors, resulting in unauthorized financial outflows. |
SAP checks for duplicate vendor invoices during non-PO (Financial Accounting) invoice entry by evaluating transaction key fields such as the vendor, company code, currency, amount, and reference invoice number. If a newly entered invoice matches a previously posted document, the system triggers an error message that blocks the duplicate posting. |
|
RTR-01
|
Record to Report |
Record to Report |
Unauthorized employees could alter G/L account definitions, classifications, or financial structures without proper oversight, leading to misclassified financial statements, incorrect reporting, or fraudulent posting paths. |
Access to create, change, or delete Chart of Accounts (CoA) or general ledger master data in SAP is restricted to authorized accounting management personnel. |
|
RTR-02
|
Record to Report |
Record to Report |
A single user acting alone could create and post unauthorized or fraudulent manual journal entries directly to the general ledger without independent review. |
SAP S/4HANA utilizes configured validation rules (via transaction OB28) and custom user exits to automatically enforce segregation of duties for manual journal entries, forcing entries to be parked and ensuring that the user who parks the journal cannot be the same user who posts it. |
|
RTR-03
|
Record to Report |
Record to Report |
A user could park a legitimate-looking journal entry and subsequently alter the amount or financial classification during the posting stage without detection, leading to unauthorized or misstated general ledger postings. |
Management periodically reviews an audit report or system logs of parked manual journal entries in SAP S/4HANA to identify and investigate any instances where the journal amount or key details were modified by the posting user after initial parking. |
|
RTR-04
|
Record to Report |
Record to Report |
Unauthorized or accidental postings to prior, closed accounting periods could alter historical financial statements, distort comparative period reporting, and violate financial close controls. |
SAP S/4HANA automatically prevents posting to closed accounting periods based on posting period variant configurations (transaction OB52), and access to alter posting period windows is strictly restricted to authorized finance personnel. |
|
RTR-05
|
Record to Report |
Record to Report |
If changes to posting periods (OB52) are made without proper authorization or oversight, unauthorized users could open closed accounting periods to post or alter transactions. This could lead to cut-off errors, untimely journal entries, and material misstatements in financial reporting. |
Management periodically reviews the history log/report of posting period maintenance (tracking changes to transaction OB52) to verify that the opening and closing of accounting periods were authorized, appropriate, and aligned with the financial close calendar. |