SAP Access & Security Audit Program — Essentials v1.0
In most SAP audits, the serious findings are about access. A leaver who can still log in. A user who can create a vendor and pay it. SAP_ALL given to someone “just for the weekend” and never taken back. A firefighter ID used with no approval and no review afterwards. These are the gaps that lead to fraud, failed SOX audits and awkward conversations with the audit committee.
The SAP Access & Security Audit Program — Essentials gives IT auditors, internal audit teams and SAP security reviewers a focused way to test the controls that decide who gets into SAP and what they can do once inside. It has 36 step-by-step procedures across 5 core sections: user lifecycle, roles and segregation of duties, password and authentication, security audit logging, and privileged accounts.
Each section starts with a plain audit objective that says what assurance it gives and which risk it prevents. The test procedures that follow each name the exact SAP T-code or report to run. You record Pass, Fail or N/A, rate the risk, write down the finding and reference your evidence, all in one workbook. Exceptions go into a consolidated Findings Log, and the Dashboard calculates pass rates for each section automatically, so you can see where the weak spots are.
It is aligned to the SAP Security Baseline, ISO 27001:2022, COBIT 2019, NIST SP 800-53 and SOX ITGC. It suits a standalone SAP access review, the access part of an ITGC audit, or a self-assessment before the external auditors arrive.
Need the full landscape? Upgrade to the complete SAP System Audit Program, which has 91 procedures across 13 sections and adds change management, batch jobs, interfaces, table access and S/4HANA.
What’s included
User Management and Account Administration (8 procedures)
Checks that only legitimate, current users have active SAP accounts. Joiners are approved, movers are adjusted, leavers are removed on time, and dormant accounts are found and dealt with.
Roles, Profiles and Authorizations (7 procedures)
Checks that access follows least privilege. It looks for SoD conflicts, toxic combinations inside composite roles, and wildcard values that give unrestricted access.
Password and Authentication Controls (7 procedures)
Checks that password policy is enforced at the parameter level and can’t be bypassed through RFC, system users or shared generic accounts.
Security Audit Log and Event Monitoring (7 procedures)
Checks that the right events are logged, kept, protected from tampering and actually reviewed, not just switched on and forgotten.
Privileged and Standard SAP Accounts (7 procedures)
Checks that SAP*, DDIC, SAP_ALL, basis admin access and firefighter IDs are locked down, justified and closely monitored.
Also included: an engagement details sheet, a key T-codes reference, a consolidated Findings Log (with root cause, impact, recommendation and management response), and an auto-scoring compliance Dashboard.










Reviews
There are no reviews yet.