RTR-04
Record to Report
Record to Report
Preventative
Automated
July 21, 2026
Control Description
SAP S/4HANA automatically prevents posting to closed accounting periods based on posting period variant configurations (transaction OB52), and access to alter posting period windows is strictly restricted to authorized finance personnel.
Risk
Unauthorized or accidental postings to prior, closed accounting periods could alter historical financial statements, distort comparative period reporting, and violate financial close controls.
Implementation Details
• Scope Entry Points: Restrict core posting period maintenance entry points, specifically classic GUI transaction OB52, generic table maintenance utilities SM30 / SM31 (when called for view V_T001B), alongside background configuration paths.
• Fiori Catalogs & OData Services: Restrict backend OData services and Fiori application paths linked to posting period management, specifically [SVC]FAC_GL_MAINT_POSTING_PERIOD_SRV and [SVC]FAC_GL_PPV_SRV, to prevent users from bypassing backend restrictions through the Fiori Launchpad.
• Control Authorization Objects: Restrict critical authorization objects associated with posting period and financial control configurations (such as object S_TABU_DIS or S_TABU_CLI with activity values for update/modify restricted specifically to table/view T001B / V_T001B).
• Monitor via SAP GRC: Build or configure a custom SAP GRC Access Risk Analysis (ARA) rule to detect and flag users holding structural authorization rights to maintain posting period windows (OB52 / view V_T001B).
• Execute Sensitive Access Analysis: Run periodic sensitive access reviews via SAP GRC to validate that posting period modification access remains strictly restricted to authorized finance management personnel.
Test Procedures
A) Test of Design (ToD):
• Inspect the SAP GRC Access Risk Analysis (ARA) ruleset configuration to verify it includes a rule checking for sensitive posting period maintenance access.
• Confirm the rule explicitly flags entry points and objects associated with posting period modifications (OB52, SM30/SM31 for view V_T001B, OData services [SVC]FAC_GL_MAINT_POSTING_PERIOD_SRV and [SVC]FAC_GL_PPV_SRV) when paired with critical authorization objects and activity values allowing the creation, change, or deletion of posting period windows.
B) Test of Operating Effectiveness (ToE):
• Inspect periodic User Access Review (UAR) sign-off logs or Access Request workflows to verify that management regularly reviews and validates who holds sensitive posting period maintenance access.