← Back to Controls

P2P-11

Business Process:
Procure to Pay
Sub-Process:
Non-PO Invoice
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 21, 2026

Control Description

Non-PO invoices received through the OpenText Vendor Invoice Management (VIM) add-on to SAP S/4HANA are routed for appropriate business approvals before posting in the financial system.

Risk

Unauthorized or fraudulent non-PO invoices could be posted and paid without proper management review and approval, resulting in unapproved expenses or financial loss.

Implementation Details

1. Incoming non-PO invoices enter VIM as a Document Processing (DP) Document.

2. VIM evaluates data against automated Business Rules;

3. Non-PO invoices specifically invoke a mandatory Approval Required rule because there is no PO baseline.

4. Chart of Authority (/n/OPT/AR_COA): Set up routing matrices defining monetary limits, company codes, and cost centers.

5. Routing Evaluation: VIM's rules engine queries the COA to identify the exact required approver based on the invoice value.

6. Approval Execution: Approvers review and approve items via SAP Fiori / Web screens.

7. Final Posting: Once the approval rule clears (turns green), VIM automatically posts the financial document in SAP.

Test Procedures

Test of Design
• Verify Document Type Configuration: Inspect VIM Customizing (/n/OPT/SPRO) to confirm that document type ZNPO_FI (Non-PO Invoice Processing) is correctly configured and mapped to the mandatory business rules, including "Approval Required."

• Review Chart of Authority (COA) Setup: Access transaction /n/OPT/AR_COA and verify that: Approval limits and monetary thresholds are correctly assigned to authorized users.

Test of Operating Effectiveness

• Population Extraction: Run transaction /n/OPT/VIM_VA2 (VIM Analytics), [or query table /OPT/VIM_1HEAD] filter by Company Code, audit period, and the Non-PO Document Type
• Select a representative sample (e.g., 25 items) across different months and approver tiers from the extracted population.
• In /n/OPT/VIM_VA2, inspect the workflow history log for each sample to confirm that the "Approval Required" exception rule triggered and halted automated posting.
• Segregation of Duties (SoD): Verify within the workflow log that the user who coded/submitted the invoice is distinct from the final approver.
• COA Limit Compliance: Cross-reference the total invoice amount against the authorized approver’s monetary limit in /n/OPT/AR_COA to ensure proper tier enforcement.