← Back to Controls

INV-01

Business Process:
Inventory
Sub-Process:
Inventory
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 27, 2026

Control Description

Access to transaction codes and authorization objects permitted to create or update material costs in SAP S/4HANA is restricted to authorized personnel

Risk

Unauthorized creation or modification of material costs in SAP S/4HANA could lead to inaccurate inventory valuation, misstatement of cost of goods sold (COGS), and material errors in financial reporting.

Implementation Details

• Scope Entry Points: Restrict core product costing and cost estimate transactions from the list—such as CK11 / CK11N (Create Material Cost Estimate), CK22 (Organizational Measure), CK40N (Edit Costing Run), CK68 (Release Costing Run), and additive cost tools (CK74N, CK75N)—to prevent unauthorized manipulation of material costs.

• Control Authorization Objects: Restrict critical authorization objects such as CK_ML_RKO (Cost Estimate with Quantity Structure) or controlling area checks in PFCG roles to ensure only authorized costing and finance personnel can create, edit, or release material cost estimates.

• Map Fiori Catalogs: Restrict Fiori equivalents for managing product cost estimates and costing runs to ensure users cannot bypass backend GUI restrictions via the Fiori Launchpad.

• Monitor via SAP GRC: Build a custom GRC ruleset to detect and audit users holding combined access to material cost creation/update transactions and standard inventory posting or logistics execution capabilities.

• Execute Sensitive Access Analysis: Run periodic sensitive access reviews via SAP GRC to validate that material costing and cost estimate maintenance access remains strictly restricted to authorized personnel.

Test Procedures

A) Test of Design (ToD)

• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it contains a custom or standard rule checking for sensitive material costing and cost estimate access.

• Confirm the rule explicitly flags the combination of core costing transactions (CK11, CK11N, CK22, CK40N, CK44, CK68, CK74N, CK75N) when paired with critical authorization objects and activity values for creating, updating, or releasing material costs.

B) Test of Operating Effectiveness (ToE)
• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds this sensitive material cost creation and update access.