P2P-01
Procure to Pay
Vendor
Preventative
Automated
July 20, 2026
Control Description
Changes to key fields in the vendor table take two people to complete; one to enter, and a second to approve.
Risk
One person acting alone could change vendor payment details without oversight
Implementation Details
Step 1: Configuration
• SPRO - IMG - > Financial Accounting->Accounts Receivable and Accounts Payable->Vendor Accounts->Master Data->Preparations for Creating Vendor Master Data->Define Sensitive Fields for Dual Control(Vendors)
•Action: Add the key fields you want to protect (e.g., Bank Details BANKN, Payment Terms ZTERM) to the table (T055F). This setting applies globally across the client.
Step 2: Day-to-Day Operations & Process Flow
1. Entry (Person 1): Modifies a protected field (e.g., bank details via BP or Maintain Business Partner).
2. System Response: SAP issues a warning stating that the vendor changes have not yet been confirmed, and marked the confirmation status as pending/unapproved.
3. Approval (Person 2): An independent user reviews the modification. via tcode: FK08 (Single) or FK09 (List) or in Fiori: Confirm Supplier List app
Test Procedures
A) Test of Design:
• Objective: Verify that SAP S/4HANA configuration enforces dual control for key/sensitive vendor master fields.
• Methodology: Inspect configuration path: SPRO -> IMG -> Financial Accounting -> Accounts Receivable and Accounts Payable -> Vendor Accounts -> Master Data -> Preparations for Creating Vendor Master Data -> Define Sensitive Fields for Dual Control (Vendors)
• Verified Fields: e.g Bank Key (LFBK-BANKL), Bank Account (LFBK-BANKN), Bank Control Key (LFBK-BKONT)
B) Test of Operating Effectiveness (ToOE)
• Objective: Test that changes to sensitive vendor fields successfully require two distinct users to enter and approve.
1. Entry: User 1 modified sensitive bank details for a selected test vendor via transaction
2. System Response: SAP issues a warning stating that the vendor changes have not yet been confirmed, and marked the confirmation status as pending/unapproved.
3. Approval (Person 2): An independent user reviews the modification. via tcode: FK08 (Single) or FK09 (List) or in Fiori: Confirm Supplier List app. User 1 cannot confirm the change