SAP: Business Process Controls and AIS Jennifer Hahn Michael Juergens Deloitte & Touche ISACA Spring Conference April 27, 1999 Presentation Outline SAP Module Overview SAP Business Process Overview Audit Information System (AIS) Overview 2 1
SAP Module Overview 3 SAP R/3 Modules PP Production Planning MM Materials Mgmt. QM Quality Management PM Plant Maintenance SD Sales & Distribution R/3 Client / Server ABAP/4 HR Human Resources FI Financial Accounting CO Controlling AM Fixed Assets Mgmt. PS Project System WF Workflow IS Industry Solutions 4 2
SAP Modules - Functional Category Functional Category Financial Applications Logistics Applications Human Resources Cross Applications Industry Solutions Financial Applications Š FI, CO, EC, IM, TR, AM, PS Logistics Applications Š SD, MM, PM, PP, QM, LO Human Resources Š PA, PD Cross Applications Š WF, OC, AL, CAD. DMS, ALE, EDI, I/Net, EC Industry Solutions Š IS 5 Financial Accounting General Ledger FI Accounts Receivable Accounts Payable Tax and Financial Reports Special Purpose Ledger Legal Consolidations Financial Applications........ 6 3
Controlling CO Cost Center Accounting Profit Center Accounting Product Cost Controlling Profitability Analysis Activity Cost Management Internal Orders Financial Applications........ 7 Fixed Asset Management Depreciation AM Property Values Insurance Policies Capital Investment Grants Financial Applications........ 8 4
Project System Project Tracking PS Work Breakdown Structure Budget Management Cost and Revenue Planning Networks and Resources Financial Applications........ 9 Sales and Distribution Computer Aided Sales SD Quotations Sales Order Management Pricing Delivery Invoicing Logistics Applications........ 10 5
Materials Management Procurement MM Inventory Management Vendor Evaluation Invoice Verification Warehouse Management Logistics Applications........ 11 Production Planning Sales & Operations Planning PP Demand Management Material Requirements Planning Production Activity Control Capacity Planning Logistics Applications........ 12 6
Quality Management QM Quality Certificates Inspection Processing Planning Tools Quality Control Quality Notifications Logistics Applications........ 13 Plant Maintenance Plant Maintenance PM Equipment and Technical Objects Preventive Maintenance Service Management Maintenance Order Management Logistics Applications........ 14 7
Human Resources Personnel Administration HR Payroll, Benefits Time Management Planning and Development Organization Management Human Resources........ 15 Cross Applications WF SAP Business Workflow SAP Office SAP ArchiveLink EDI Communication Application Link Enabled (ALE) Others Cross Applications........ 16 8
Industry Solutions IS Banks Hospitals Oil Companies Publishing Sector Telecommunications Retail Utilities Others Industry Solutions........ 17 Basis Component Overview 18 9
Basis Component BC ABAP/4 Development Workbench Computer Center Management System Authorization Concept Transport System Database Administration Basis Component........ 19 SAP Business Process Overview 20 10
SAP Business Processes Over 1200 business processes defined by SAP Highly flexible Customized to fit each company Companies choose the business processes that they want to implement Every SAP installation is different It is important to have clear understanding of business processes that are effected by the SAP implementation These business processes should be mapped to the corresponding SAP modules that are implemented 21 Example Business Process - Sales Planning MPS Product Costing Profitability Analysis Sales Order MRP run Planned Order Production Order Delivery Billing Customer Payment Goods Issue Goods Receipt Goods Issue Vendor Customer Purchase Requisition Raw Goods Receipt Finished Modules MM PP G/L Account Material Purchase Order Invoice Receipt Vendor Payment SD FI/CO 22 11
Linking SAP Modules, Business Processes and Audit 23 Audit Challenges SAP Modules Three Main Functional Categories Multitude of Modules Multitude of Sub-Modules SAP Business Processes 1200+ Processes Audit Processes Business Process Cycles 24 12
Linking Audit Cycles to SAP Modules Audit Business Cycles Treasury Fixed Assets Expenditure Revenue Inventory Management Payroll and Personnel SAP Module Functional Category Financial Applications Logistics Applications Human Resources Basis Component Cross Applications Industry Solutions 25 Audit Information System (AIS) 26 13
Requested by AIS - History and Background Internal Auditors, External Auditors, and Company Management Designed by SAP in response to requirements for a tool to find, evaluate and download information from SAP easily Includes: Audit Report Tree (transaction code: SECR) Report tree includes Systems and Financial audit tasks, reports and tests for additional modules are under development Evaluation and notes can be entered into the specific tasks to monitor progress of tasks 27 AIS - History and Background To provide a mechanism and structure for collection, and presentation of standard SAP reporting The goal is improvement of audit quality through real-time auditing SAP - DB A I S To provide company specific, individual selection and preparation of data needs and requirements for reporting and review To provide the ability to download data into flat files for analysis with external tools AuditAgent ACL IDEA Baetge 28 14
What is AIS? A collection of SAP reports / queries based on a reporting tree A tool for auditing an SAP system Utilizes existing SAP functionality Designed to rationalize and facilitate the audit process Organizes all audit related activities under one umbrella Aims to improve the quality of an audit 29 What does AIS do? 1998 SAP AG. All rights reserved. 30 15
What does AIS do? 1998 SAP AG. All rights reserved. 31 AIS Features and Functions Tool for performing both System and Business Audits Provides auditors with the ability to document and monitor the progress of an audit Reports and queries can be customized for each user Allows auditors to evaluate information or download data to be used by CAAT tools such as ACL Different views allow external auditors (both financial and systems auditors) and internal auditors to use the system simultaneously 32 16
AIS - System Audits Using the AIS System Audit tree users can: Review system configuration settings Review parameters settings Monitor operations Review various logs Review background processing Review security settings Perform user security audits Review transport related activities Review print and spool administration 33 AIS - Business Audits Using the AIS Business Audit tree users can: Perform various audit related queries Produce various audit related reports Review organization structure Review document structure, ranges, posting keys etc. Review client setup (number of accounts, assets, customers, vendors, materials etc.) Review chart of accounts Produce financial reports (balance sheets, P&L, ratio analysis etc.) Review account balances 34 17
Audit Status Analysis AIS uses Status Analysis functionality to: Summarize, maintain and monitor details of the audit progress of specific testing, and for audit management Easily and quickly identify problem areas Document results of tests offering drill-down functionality Notes exist in SAP R/3 version 3.1G+ 35 Audit Status Analysis Status Analysis functionality and capabilities improves the ability of Audit management to track tasks performed within SAP: Percentage of completed audit steps for an audit objective via traffic lights: Creation of separate documentation for the node of each separate user view Ability to identify the number of views a node is assigned to, with the associated status of completion for each view Tracking of changes made to the notes to a responsible person 36 18
Audit Status Analysis 37 Audit Report Tree The audit report tree contains two standard views: Financial Audit (AUDIT_FI) Systems Audit (AUDIT_SECR) Each view contains: Auditing procedures and documentation tools Audit evaluations (including data and key controls within the configuration) Data download tools through links to Data Analysis Tools, such as ACL (automated) or IDEA (through Monarch) 38 19
Audit Report Tree 39 AIS and SAP versions Versions 3.1I and 4.5B+ An integral part of the SAP Basis Component Only works on certain releases of R/3 3.0D, 3.0E, 3.0F 3.1G, 3.1H, 3.1I 4.0A, 4.0B, 4.0C 4.5A, 4.5B, 4.6A Not all functions are available in each version, as functionality is based on the release level 40 20
AIS - Relevant OSS Notes Online System Support (OSS) Notes: 13719 - Transport Files to load AIS onto SAP for versions 3.0D on 41475 - Copying report variants between clients 77503 - AIS Overview, Auditor s configuration of Views, Variants and Ratios 85344 - Performance concerns when AIS is installed 100609 - Basis Installation Steps 128256 - Missing English Texts 129170 - Download of Query Data 133914 - Conversion of drill-down reports 41 AIS Business Case 42 21
AIS Advantages Centralized auditing Continuous auditing Teaming of internal and external audit efforts More efficient use of time One report tree Simplify data extraction Potential to have all SAP reports in AIS only Custom views AIS is free 43 AIS Disadvantages Variant review after every SAP upgrade Reports must be configured SAP knowledge required to interpret results Over auditing Under auditing Access to SAP Auditability of the Financial (FI) module Only Reliance on the SAP system is assumed AIS is not mature 44 22
Questions and Information Presenter Information: Jennifer Hahn 714-436-7171 Michael Juergens 714-436-7276 45 23