← Back to Controls

OTC-03

Business Process:
Order to Cash
Sub-Process:
Pricing Master Data
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 21, 2026

Control Description

Access to create, change, or delete sales pricing conditions is restricted to authorized pricing or finance personnel.

Risk

Unauthorized employees could alter product prices or discounts without proper review, leading to incorrect customer billings, revenue leakage, or unauthorized sales concessions.

Implementation Details

• Scope Entry Points: Restrict core pricing transactions (VK11, VK12, VK14, and mass tools VK31 / VK32) to prevent unauthorized manipulation of sales pricing conditions.

• Map Fiori Catalogs: Restrict Fiori equivalents for managing price condition records to ensure users cannot bypass backend restrictions through the Fiori Launchpad.

• Monitor via SAP GRC: Build a custom GRC ruleset to detect and audit users holding pricing condition maintenance rights.

• Execute Sensitive Access Analysis: Run periodic sensitive access reviews via SAP GRC to validate that pricing modification access remains restricted.

Test Procedures

Test of Design (ToD):

• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it contains a custom or standard rule checking for sensitive sales pricing access.

• Confirm the rule explicitly flags users with core condition maintenance transactions (VK11, VK12, VK14, or mass tools VK31 / VK32) when paired with critical authorization objects and activity values for creating, changing, or deleting pricing conditions.

Test of Operating Effectiveness (ToE):

• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds this sensitive pricing and condition maintenance access.