← Back to Controls

A2R-01

Business Process:
Acquire to Retire
Sub-Process:
Asset Master Data
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 24, 2026

Control Description

Management enforces restrictions on fixed asset master data by assigning transaction-level authorizations (such as AS01 and AS02 for creation and modification) exclusively to authorized accounting personnel

Risk

Unauthorized personnel could create fraudulent asset records or modify asset master parameters (such as useful lives, cost centers, or capitalization dates), leading to misstated asset values and improper financial reporting

Implementation Details

• Scope Entry Points: Restrict core master data creation/modification transactions (AS01, AS02, AS21, AS22, AS24), blocking/deletion tools (AS05, AS06, AS25, AS26), and posting/transactional entry points (ABZOL, F-90) to prevent unauthorized manipulation of fixed assets.

• Control Authorization Objects: Restrict critical authorization objects such as A_S_ANL01 (Asset Accounting: Master Data - Company Code / Asset Class) and F_BKPF_BUK (Company Code authorizations) in PFCG roles to ensure only authorized accounting personnel can create or alter fixed assets.

• Map Fiori Catalogs: Restrict Fiori equivalents for managing fixed asset master data (such as apps for Create Asset Master Record or Manage Fixed Assets) to ensure users cannot bypass backend GUI restrictions via the Fiori Launchpad.

• Monitor via SAP GRC: Build a custom GRC ruleset to detect and audit users holding access to Fixed Asset master data creation

• Execute Sensitive Access Analysis: Run periodic sensitive access reviews via SAP GRC to validate that fixed asset master remains restricted to authorized personnel.

Test Procedures

A) Test of Design (ToD)
• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it contains a custom or standard rule checking for sensitive fixed asset master data and posting access.

• Confirm the rule flags the combination of fixed asset maintenance transactions (AS01, AS02, AS05, AS06, AS21, AS22, AS24, AS25, AS26, ABZOL, F-90) when paired with critical authorization objects (such as A_S_ANL01) and activity values for creating, changing, or deleting fixed asset records.

B) Test of Operating Effectiveness (ToE)

• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds this sensitive fixed asset master data and accounting maintenance access.