SAP SOX Compliance


What Is SOX Compliance?

The Sarbanes-Oxley Act (SOX) of 2002 requires financial transparency by U.S. public companies, ensuring their data is secure and accurate. Drafted by Congressmen Paul Sarbanes and Michael Oxley following several U.S. corporate and financial scandals, SOX compliance means having a formalized system for internal controls — one that provides full financial transparency.

In a blog post, the criticality of SAP governance, risk management, and compliance (GRC) for SOX compliance is explored. The author points out that two sections (Section 302 and Section 404) are the most important and relevant for SAP GRC and finance users.

What Is SOX Compliance?

The Sarbanes-Oxley Act (SOX) of 2002 requires financial transparency by U.S. public companies, ensuring their data is secure and accurate. Drafted by Congressmen Paul Sarbanes and Michael Oxley following several U.S. corporate and financial scandals, SOX compliance means having a formalized system for internal controls — one that provides full financial transparency.

In a blog post, the criticality of SAP governance, risk management, and compliance (GRC) for SOX compliance is explored. The author points out that two sections (Section 302 and Section 404) are the most important and relevant for SAP GRC and finance users.

An SAP SOX compliance checklist should address the following:

  • Segregation of duties
  • SAP GRC monitoring
  • Safeguard SOX audit trails against emergency access
  • Automate SAP audit reporting

Further Resources for SAPinsiders

Accounting & Finance Expands Its Influence. In this article, learn how UGI Utilities developed a strategic roadmap to better anticipate internal and external demands on the business — including regulations such as SOX. The utility shares how using BlackLine and its task functionality provides intuitive controls for SOX compliance.

Beyond SOX: Addressing non-financial risks through SAP configuration and sound supporting processes. Often, compliance is a focal point during SAP implementation to ensure compliance with financial reporting and regulations, such as SOX. However, there are optional SAP controls that could provide even more value to companies’ SAP system and supporting processes. In this session, Steve Biskie from RSM shares how to minimize and mitigate operational and strategic risks through SAP configuration. Understand who in the organization should be involved in recommending and validating control changes, and how to set up an appropriate cross-functional team to ensure decisions are sound and don’t introduce other risks.

Bridging the Cybersecurity Gap in IT General Controls (ITGC). Compliance with regulations like SOX often require a set of controls in place to mitigate risks to the integrity of financial reporting. Current ITGC testing performed by internal and external auditors is only focused on one slice of access risk. In this session, Brian Tremblay from Onapsis shares why it’s critical to understand the threats that exist to your SAP system beyond the current ITGC scope and how they relate to compliance with SOX.

 

A vendor that can help SAP customers with SOX compliance is Appsian Security. The provider offers a single platform for automating how users secure user identity, govern access, detect and prevent fraud, and demonstrate compliance with SOX, the General Data Protection Regulation, and more across critical business applications.  

969 results

  1. Decoding the Cost Object Mapping Framework in SAP Central Finance

    Published: 29/September/2017

    Reading time: 13 mins

    Learn about the concept, purpose, configuration, and execution of the cost object mapping framework in SAP Central Finance. Key Concept SAP Central Finance in SAP S/4HANA offers a new configuration for the cost object mapping framework, which is mainly used for short-living cost objects such as an internal order, a production order, or a service...…

  2. Part 2: Plan For and Implement SAP Learning Solution

    Published: 15/November/2006

    Reading time: 32 mins

    SAP Learning Solution (LSO) configuration builds on SAP Training Management configuration. Follow these expert tips that relate to Training Management and LSO. Understand key configuration decisions before moving into your blueprint phase to configure LSO quickly and painlessly. Key Concept Your blueprint documentation should describe your key business processes and mirror the structure of the...…

  3. Part 3: Plan for and Implement SAP Learning Solution’s Authoring Environment

    Published: 15/December/2006

    Reading time: 22 mins

    SAP Authoring Environment, a component of SAP Learning Solution, allows course authors and instructional designers to design and structure Web-based training content and tests. Learn about the key functionalities of Authoring Environment and discover undocumented tips about how to use Authoring Environment successfully. Key Concept SAP Authoring Environment is a locally installed application in SAP...…

  4. Fully Integrate Your SAP HANA Database Procedures into ABAP with AMDP

    Published: 21/December/2015

    Reading time: 20 mins

    ABAP Managed Database Procedures (AMDP) is a new technology to embed native database source code into ABAP applications. With the current focus on SAP HANA, ABAP developers now can use database features beyond the scope of Open SQL. AMDPs are available with SAP NetWeaver 7.40 Support Package 5 though some features described here require subsequent...…

  5. Live from SAPinsider Studio: Rohana Gunawardena on SAP CO

    Rohana Gunawardena, Director, SAP Practice, QS&S, joins SAPinsider Studio at the SAPinsider FIN 2016 event in Las Vegas to discuss the SAP CO philosophy and using CO beyond cost center accounting, such as internal orders, as well as what SAP S/4HANA means for SAP CO. This is an edited version of the transcript: Ken Murphy,…

  6. A Roadmap to the Digital Retailing Era

    Published: 10/November/2017

    Reading time: 10 mins

    Ken Murphy, SAPinsider: This is Ken Murphy with SAPinsider. The evolution of technology and digital transformation is having a tremendous impact across industry types, but perhaps nowhere are these forces having a greater impact than retail and fashion. Traditional methods of selling goods and products to end consumers are quickly being replaced by omnichannel offerings…

  7. What to Expect From Our SAPinsider 2020 Event: Insights From Rizal Ahmed, President and Head of Research, SAP S/4HANA and Cloud at SAPinsider

    Published: 24/January/2020

    Reading time: 2 mins

    On March 17-19 in Vegas this year at SAPinsider’s 2020 conference the word that will be buzzing around every room in the Bellagio is SAP S/4HANA, and for good reason. From our research we know that moving to SAP’s latest upgrade is the most consuming, important decision and project that SAP customers are facing, and…

  8. A Look at Current SAP Marketplace Trends

    Published: 16/January/2020

    Reading time: 3 mins

    SAPinsider recently sat down with an expert in the SAPinsider community, Rohana Gunawardena, Director – SAP Practice, Exium Inc., to discuss some of the trends he’s seeing in the marketplace. A Major Priority for Finance Company CFOs A big priority for SAP customers in the finance industry right now, says Rohana, is making the monthly…

  9. Your SAP Peers Want to Hear from You!

    Published: 12/January/2020

    Reading time: 2 mins

    In talking with SAPinsider members we’ve learned that many of you have a real desire to share your strategic insights, business best practices, functional tips, and road-tested advice with your SAP peers. SAPinsider wants to harness that knowledge and catapult it out to the larger SAP community by partnering with you, our readers. We’re currently…

  10. Akash Kumar image

    Members Who Inspire | Akash Kumar

    Published: 01/December/2021

    Reading time: 2 mins

    Name: Akash Kumar Job Position: Solution Architect Company: HCL LinkedIn: https://www.linkedin.com/in/akashkumar1987/  Twitter: https://twitter.com/akashkumar1987 How did you first hear about SAPinsider? I first came across SAPinsider at the SAPinsider booth in the 2018 SAP SAPPHIRENOW Conference, which was my first ever SAPPHIRE event and have been a member since. If you had four more hours in your day,…