← Back to Controls

OTC-02

Business Process:
Order to Cash
Sub-Process:
Credit master data
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 21, 2026

Control Description

Access to modify credit limit and risk category fields in the customer master record is restricted to authorized credit management personnel.

Risk

Unauthorized employees could alter customer credit limits or risk categories without proper review, leading to excessive credit exposure, unapproved credit extensions, and potential bad debt write-offs.

Implementation Details

• Scope Entry Points: Restrict core transaction BP and mass update tools (UKM_MASS_UPD1 through UKM_MASS_UPD5) to prevent unauthorized master data manipulation.

• Control BP Roles via authorization object B_BUPA_RLT: Restrict authorization object B_BUPA_RLT in PFCG roles so that non-credit personnel cannot assign or edit role UKM000 (Credit Management).

• Map Fiori Catalogs: Restrict Fiori equivalents credit management apps to ensure users cannot bypass backend restrictions through the Fiori Launchpad.

• Monitor via SAP GRC: Build a custom GRC ruleset to detect and audit users holding combined access to transaction BP and change rights for credit management objects.

• Execute sensitive access analysis quarterly via SAP GRC

Test Procedures

Test of Design (ToD):

• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it contains a custom or standard rule checking for sensitive access.

• Confirm the rule explicitly flags the combination of core master data transaction BP (or relevant mass update t-codes like UKM_MASS_UPD1 and UKM_MASS_UPD2) when paired with authorization object B_BUPA_RLT restricted to role UKM000 (Credit Management).

Test of Operating Effectiveness (ToE):

• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds this sensitive credit management access.