← Back to Controls

RTR-01

Business Process:
Record to Report
Sub-Process:
Record to Report
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 21, 2026

Control Description

Access to create, change, or delete Chart of Accounts (CoA) or general ledger master data in SAP is restricted to authorized accounting management personnel.

Risk

Unauthorized employees could alter G/L account definitions, classifications, or financial structures without proper oversight, leading to misclassified financial statements, incorrect reporting, or fraudulent posting paths.

Implementation Details

• Scope Entry Points: Restrict core General Ledger master data and Chart of Accounts transactions, specifically FS00 (G/L Account Centrally), FS01 (Create G/L Account in Chart of Accounts - classic), FS02 (Change G/L Account in Chart of Accounts - classic), FSS0, FSS1, and FSS2 (Company Code level maintenance), alongside global Chart of Accounts configuration tools like OBY2 and OBY7 to prevent unauthorized structural financial changes.

• Control Authorization Objects: Restrict authorization objects such as F_BKPF_KOA (G/L account authorization by account type

• Map Fiori Catalogs: Restrict Fiori equivalents for managing G/L accounts and master data (such as apps for Manage G/L Account Master Data or Maintain Chart of Accounts) to prevent users from bypassing backend restrictions through the Fiori Launchpad.

Monitor via SAP GRC: Build a custom GRC ruleset to detect and audit users holding access to GL master data creation or modification rights for the Chart of Accounts.

Execute Sensitive Access Analysis: Run periodic sensitive access reviews via SAP GRC to validate that Chart of Accounts and G/L master data maintenance access remains strictly restricted to authorized accounting management personnel.

Test Procedures

A) Test of Design (ToD):

• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it contains a custom or standard rule checking for sensitive general ledger and Chart of Accounts master data access.

• Confirm the rule explicitly flags the combination of core G/L account maintenance and Chart of Accounts transactions (FS00, FS01, FS02, FSS0, FSS1, FSS2, OBY2, OBY7, OT42) when paired with critical authorization objects (such as F_BKPF_KOA) and activity values for creating, changing, or deleting financial master data.

B) Test of Operating Effectiveness (ToE):

• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds this sensitive Chart of Accounts and G/L master data maintenance access.