A2R-02
Acquire to Retire
Internal Order
Preventative
Automated
July 24, 2026
Control Description
Management enforces access restrictions within SAP S/4HANA to ensure that the creation, modification, and settlement of internal orders dedicated to Construction in Progress (restricted to specific capital order types) are limited strictly to authorized project accounting and finance personnel via transaction codes KO01, KO02, and KO04.
Risk
Unauthorized employees could open or manipulate capital internal orders, leading to misallocated capital expenditures, improper capitalization of operating expenses, or delayed asset depreciation.
Implementation Details
• Scope Entry Points: Restrict core internal order creation, modification, and management transactions (KO01, KO02, and KO04) to prevent unauthorized manipulation of capital orders.
• Control Order Types via Authorization Object AUFART: Restrict authorization object AUFART (Order Type) in PFCG roles so that users can only create or edit specific capital/CIP order types (populating AUFART exclusively with the exact internal order types designated for Construction in Progress) rather than general overhead orders.
• Map Fiori Catalogs: Restrict Fiori equivalents for managing internal orders (such as apps for Create Internal Order or Manage Internal Orders) to ensure users cannot bypass backend GUI restrictions via the Fiori Launchpad.
• Monitor via SAP GRC: Build a custom GRC ruleset to detect and audit users holding access to internal order master data maintenance for those internal order types used ty manage CIP
Execute Sensitive Access Analysis: Run periodic sensitive access reviews via SAP GRC to validate that CIP internal order maintenance access remains strictly restricted to authorized personnel.
Test Procedures
A) Test of Design (ToD)
• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it contains a custom or standard rule checking for sensitive internal order and capital project access.
• Confirm the rule explicitly flags the combination of core internal order transactions (KO01, KO02, KO04) when paired with authorization object AUFART restricted to the specific order types used for CIP.
Test of Operating Effectiveness (ToE)
• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds this sensitive CIP internal order creation and modification access.