cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Business ByDesign IT Audit reports - SOX

0 Kudos

Greetings Community,

My company just migrated into SAP ByDesign.
After all successful implementations, we are facing a problem IT audit reports. For the SOX audit purpose, we need to have an integration audit reports that would tell us what was changed - reports, integrations, configurations. We have found few reports that would show us a software history, access right change, and a few other reports which would point us to a small overview of possible SAP changes that most definitely would not satisfy auditors.

So, my question to the community. How other SAP ByDesign clients handle SOX reports within SAP?

Please help.

Thank you

Alex Babych

WolfgangK
Explorer
0 Kudos

Dear Alex,

thanks for your post, we are in a comparable situation at one of our customers. Have you had the chance to go ahead with this topic, how did you solve the requirment with SOX.

Thanks for your feedback.

With best regards,

Wolfgang Kroener

Accepted Solutions (0)

Answers (1)

Answers (1)

0 Kudos

Greetings Wolfgang,

Unfortunately, we have not found a solution within SAP ByD to track all IT compliance items. We are using Boomi to track any integration change. We also had to put a restriction on a user's access and use our ticketing system to track any change within SAP.

Also, SAP does not provide any specific area where we could find all compliance reports, thus, we have to look all over the place to find something that would fit our requirements. Some of the data in SAP, that we need to report to auditors we cannot even print out nor export; therefore, we have to use screenshots and other magic tricks to get reportable information out of SAP.

Here are some thoughts on compliance.

  1. Business Configuration/Reports - work center
    a. Configuration Change History – reports on Scoping, Questions, Fine-Tuning Settings. Sample Reports attached:
  • i.Change History of Scoping
  • ii.Change History of Questions
  • iii.Fine-Tuning Reports – Chart of Accounts, Financial Reporting Structure, Account Determination
  • iv.Fine Tuning Reports – Fixed Asset Classes
    b. Solution Proposal – Executive Summar

2.Summary of Fixed Assets Changes – We managed to create a report. Many different parameters are available within FA data source.

As mentioned, we have restricted access to users and if any change needs to be done, we use a ticketing system to outline any change and then a user gets access to the system to perform this or that task. On the weekly base, we run the following reports to catch and tie SAP access change to our tickets.

  1. Report: All Business Roles
  1. Report: All Current Access Rights
  1. Report: Access Rights Change Log