Professional Documents
Culture Documents
Jennifer Hahn Michael Juergens Deloitte & Touche ISACA Spring Conference April 27, 1999
Presentation Outline
SAP: Business Process Controls and AIS
SAP Module Overview s SAP Business Process Overview s Audit Information System (AIS) Overview
s
Bpcontrols.ppt
Bpcontrols.ppt
SD
Sales & Distribution
FI
Financial Accounting
MM PP
Materials Mgmt. Production Planning
CO
Controlling
AM
R/3
Client / Server ABAP/4
HR IS
Industry Solutions
QM
Quality Management
PS
Project System
PM
Plant Maintenance
WF
Workflow
Human Resources
Bpcontrols.ppt
Functional Category
s s s s
Financial Applications Logistics Applications Human Resources Cross Applications Industry Solutions
Financial Applications
FI, CO, EC, IM, TR, AM, PS
Logistics Applications
SD, MM, PM, PP, QM, LO
Human Resources
PA, PD
Cross Applications
WF, OC, AL, CAD. DMS, ALE,
EDI, I/Net, EC s
Industry Solutions
IS
5
Bpcontrols.ppt
Financial Accounting
SAP: Business Process Controls and AIS
q q
General Ledger Accounts Receivable Accounts Payable Tax and Financial Reports Special Purpose Ledger Legal Consolidations
FI
q q
q q
Financial Applications. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
Controlling
SAP: Business Process Controls and AIS
q q
Cost Center Accounting Profit Center Accounting Product Cost Controlling Profitability Analysis Activity Cost Management Internal Orders
CO
q q
Financial Applications. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
q q q q
AM
Financial Applications. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
Project System
SAP: Business Process Controls and AIS
q q
Project Tracking Work Breakdown Structure Budget Management Cost and Revenue Planning Networks and Resources
PS
q q
Financial Applications. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
Computer Aided Sales Quotations Sales Order Management Pricing Delivery Invoicing
SD
q q q q
Logistics Applications . . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
10
Materials Management
SAP: Business Process Controls and AIS
q q q q q
MM
Logistics Applications . . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
11
Production Planning
SAP: Business Process Controls and AIS
q
Sales & Operations Planning Demand Management Material Requirements Planning Production Activity Control Capacity Planning
PP
Logistics Applications . . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
12
Quality Management
SAP: Business Process Controls and AIS
Quality Certificates Inspection Processing Planning Tools Quality Control Quality Notifications
QM
q q q q
Logistics Applications . . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
13
Plant Maintenance
SAP: Business Process Controls and AIS
q q
Plant Maintenance Equipment and Technical Objects Preventive Maintenance Service Management Maintenance Order Management
PM
q q q
Logistics Applications . . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
14
Human Resources
SAP: Business Process Controls and AIS
q
Personnel Administration Payroll, Benefits Time Management Planning and Development Organization Management
HR
q q
Human Resources. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
15
Cross Applications
SAP: Business Process Controls and AIS
q q q
WF
q q q
SAP Business Workflow SAP Office SAP ArchiveLink EDI Communication Application Link Enabled (ALE) Others
Cross Applications. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
16
Industry Solutions
SAP: Business Process Controls and AIS
q q q
IS
q q q q q
Banks Hospitals Oil Companies Publishing Sector Telecommunications Retail Utilities Others
Industry Solutions. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
17
Bpcontrols.ppt
18
Basis Component
SAP: Business Process Controls and AIS
q
ABAP/4 Development Workbench Computer Center Management System Authorization Concept Transport System Database Administration
BC
q q q
Basis Component. . . . . . . .
1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
19
Bpcontrols.ppt
20
10
Bpcontrols.ppt
21
Planning MPS
Sales Order
MRP run
Planned Order
Production Order
Delivery
Billing
Customer Payment
Goods Issue
Goods Receipt
Goods Issue
Purchase Requisition
Raw
Goods Receipt
Finished
Modules s MM s PP
Invoice Receipt
Vendor Payment
s SD s FI/CO
Bpcontrols.ppt
22
11
Bpcontrols.ppt
23
Audit Challenges
SAP: Business Process Controls and AIS
SAP Modules
Three Main Functional Categories Multitude of Modules Multitude of Sub-Modules
Audit Processes
Business Process Cycles
Bpcontrols.ppt
24
12
Audit Business Cycles Treasury Fixed Assets Expenditure Revenue Inventory Management Payroll and Personnel
Logistics Applications
Human Resources
Basis Component Cross Applications Industry Solutions
Bpcontrols.ppt
25
Bpcontrols.ppt
26
13
Requested by
Internal Auditors, External Auditors, and Company Management
Designed by SAP in response to requirements for a tool to find, evaluate and download information from SAP easily Includes:
Audit Report Tree (transaction code: SECR) Report tree includes Systems and Financial audit tasks, reports and tests for additional modules are under development Evaluation and notes can be entered into the specific tasks to monitor progress of tasks
Bpcontrols.ppt
27
To provide a mechanism and structure for collection, and presentation of standard SAP reporting The goal is improvement of audit quality through real-time auditing To provide company specific, individual selection and preparation of data needs and requirements for reporting and review To provide the ability to download data into flat files for analysis with external tools
AuditAgent ACL IDEA Baetge
IS
s
SAP - DB
1999 Deloitte & Touche LLP. All rights reserved.
Bpcontrols.ppt
28
14
What is AIS?
SAP: Business Process Controls and AIS
s s s
A collection of SAP reports / queries based on a reporting tree A tool for auditing an SAP system Utilizes existing SAP functionality Designed to rationalize and facilitate the audit process Organizes all audit related activities under one umbrella Aims to improve the quality of an audit
Bpcontrols.ppt
29
1998 SAP AG. All rights reserved. 1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
30
15
1998 SAP AG. All rights reserved. 1999 Deloitte & Touche LLP. All rights reserved. Bpcontrols.ppt
31
s s s s
Tool for performing both System and Business Audits Provides auditors with the ability to document and monitor the progress of an audit Reports and queries can be customized for each user Allows auditors to evaluate information or download data to be used by CAAT tools such as ACL Different views allow external auditors (both financial and systems auditors) and internal auditors to use the system simultaneously
Bpcontrols.ppt
32
16
Bpcontrols.ppt
33
Bpcontrols.ppt
34
17
Bpcontrols.ppt
35
Status Analysis functionality and capabilities improves the ability of Audit management to track tasks performed within SAP:
Percentage of completed audit steps for an audit objective via traffic lights: Creation of separate documentation for the node of each separate user view Ability to identify the number of views a node is assigned to, with the associated status of completion for each view Tracking of changes made to the notes to a responsible person
Bpcontrols.ppt
36
18
Bpcontrols.ppt
37
Bpcontrols.ppt
38
19
Bpcontrols.ppt
39
Not all functions are available in each version, as functionality is based on the release level
Bpcontrols.ppt
40
20
Bpcontrols.ppt
41
Bpcontrols.ppt
42
21
AIS Advantages
SAP: Business Process Controls and AIS
s s s s s s s s s
Centralized auditing Continuous auditing Teaming of internal and external audit efforts More efficient use of time One report tree Simplify data extraction Potential to have all SAP reports in AIS only Custom views AIS is free
Bpcontrols.ppt
43
AIS Disadvantages
SAP: Business Process Controls and AIS
s s s s s s s s s
Variant review after every SAP upgrade Reports must be configured SAP knowledge required to interpret results Over auditing Under auditing Access to SAP Auditability of the Financial (FI) module Only Reliance on the SAP system is assumed AIS is not mature
Bpcontrols.ppt
44
22
Presenter Information:
Jennifer Hahn 714-436-7171 Michael Juergens 714-436-7276
Bpcontrols.ppt
45
23