A2R-01
Acquire to Retire
Asset Master Data
Preventative
Automated
July 24, 2026
Control Description
Management enforces restrictions on fixed asset master data by assigning transaction-level authorizations (such as AS01 and AS02 for creation and modification) exclusively to authorized accounting personnel
Risk
Unauthorized personnel could create fraudulent asset records or modify asset master parameters (such as useful lives, cost centers, or capitalization dates), leading to misstated asset values and improper financial reporting
Implementation Details
• Scope Entry Points: Restrict core master data creation/modification transactions (AS01, AS02, AS21, AS22, AS24), blocking/deletion tools (AS05, AS06, AS25, AS26), and posting/transactional entry points (ABZOL, F-90) to prevent unauthorized manipulation of fixed assets.
• Control Authorization Objects: Restrict critical authorization objects such as A_S_ANL01 (Asset Accounting: Master Data - Company Code / Asset Class) and F_BKPF_BUK (Company Code authorizations) in PFCG roles to ensure only authorized accounting personnel can create or alter fixed assets.
• Map Fiori Catalogs: Restrict Fiori equivalents for managing fixed asset master data (such as apps for Create Asset Master Record or Manage Fixed Assets) to ensure users cannot bypass backend GUI restrictions via the Fiori Launchpad.
• Monitor via SAP GRC: Build a custom GRC ruleset to detect and audit users holding access to Fixed Asset master data creation
• Execute Sensitive Access Analysis: Run periodic sensitive access reviews via SAP GRC to validate that fixed asset master remains restricted to authorized personnel.
Test Procedures
A) Test of Design (ToD)
• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it contains a custom or standard rule checking for sensitive fixed asset master data and posting access.
• Confirm the rule flags the combination of fixed asset maintenance transactions (AS01, AS02, AS05, AS06, AS21, AS22, AS24, AS25, AS26, ABZOL, F-90) when paired with critical authorization objects (such as A_S_ANL01) and activity values for creating, changing, or deleting fixed asset records.
B) Test of Operating Effectiveness (ToE)
• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds this sensitive fixed asset master data and accounting maintenance access.