SAP SOX Compliance


What Is SOX Compliance?

The Sarbanes-Oxley Act (SOX) of 2002 requires financial transparency by U.S. public companies, ensuring their data is secure and accurate. Drafted by Congressmen Paul Sarbanes and Michael Oxley following several U.S. corporate and financial scandals, SOX compliance means having a formalized system for internal controls — one that provides full financial transparency.

In a blog post, the criticality of SAP governance, risk management, and compliance (GRC) for SOX compliance is explored. The author points out that two sections (Section 302 and Section 404) are the most important and relevant for SAP GRC and finance users.

What Is SOX Compliance?

The Sarbanes-Oxley Act (SOX) of 2002 requires financial transparency by U.S. public companies, ensuring their data is secure and accurate. Drafted by Congressmen Paul Sarbanes and Michael Oxley following several U.S. corporate and financial scandals, SOX compliance means having a formalized system for internal controls — one that provides full financial transparency.

In a blog post, the criticality of SAP governance, risk management, and compliance (GRC) for SOX compliance is explored. The author points out that two sections (Section 302 and Section 404) are the most important and relevant for SAP GRC and finance users.

An SAP SOX compliance checklist should address the following:

  • Segregation of duties
  • SAP GRC monitoring
  • Safeguard SOX audit trails against emergency access
  • Automate SAP audit reporting

Further Resources for SAPinsiders

Accounting & Finance Expands Its Influence. In this article, learn how UGI Utilities developed a strategic roadmap to better anticipate internal and external demands on the business — including regulations such as SOX. The utility shares how using BlackLine and its task functionality provides intuitive controls for SOX compliance.

Beyond SOX: Addressing non-financial risks through SAP configuration and sound supporting processes. Often, compliance is a focal point during SAP implementation to ensure compliance with financial reporting and regulations, such as SOX. However, there are optional SAP controls that could provide even more value to companies’ SAP system and supporting processes. In this session, Steve Biskie from RSM shares how to minimize and mitigate operational and strategic risks through SAP configuration. Understand who in the organization should be involved in recommending and validating control changes, and how to set up an appropriate cross-functional team to ensure decisions are sound and don’t introduce other risks.

Bridging the Cybersecurity Gap in IT General Controls (ITGC). Compliance with regulations like SOX often require a set of controls in place to mitigate risks to the integrity of financial reporting. Current ITGC testing performed by internal and external auditors is only focused on one slice of access risk. In this session, Brian Tremblay from Onapsis shares why it’s critical to understand the threats that exist to your SAP system beyond the current ITGC scope and how they relate to compliance with SOX.

 

A vendor that can help SAP customers with SOX compliance is Appsian Security. The provider offers a single platform for automating how users secure user identity, govern access, detect and prevent fraud, and demonstrate compliance with SOX, the General Data Protection Regulation, and more across critical business applications.  

969 results

  1. How to Set Up the Fiori Clear Incoming Payments App for Use in a Launchpad

    Published: 18/December/2015

    Reading time: 12 mins

    SAP S/4HANA Finance delivers improved business processes with a new user experience. Transactions that have not been changed in 15 years have received a complete face-lift, and how users access the transactions within their processes has also completely changed. Learn the technical aspects of the Fiori interface implementation based on a classic accounts receivable (FI-AR)...…

  2. Special Report: Implementing SAP HANA – An End-to-End Perspective

    Published: 17/October/2012

    Reading time: 69 mins

    In this exclusive special report, get an in-depth, step-by-step look at the aspects of implementing BI solutions on SAP HANA. Gain insight into how ETL integrates with SAP HANA and how SAP BusinessObjects BI 4.0 analyzes and visualizes the data stored in SAP HANA. Key Concept SAP HANA modeling is a process whereby a developer...…

  3. Data Owner Responsibilities and Characteristics

    Published: 12/August/2010

    Reading time: 31 mins

    Authored by Vinod Reddy, Data Migration and SAP MM Techno Functional Consultant, Utopia, Inc.   Every enterprise will definitely have the objective to improve efficiency and effectiveness in managing data. Efficiency will result in minimizing the cost of administering data and effectiveness will result in maximizing the data quality. From my perspective, a data owner should…

  4. Live from SAPinsider Studio: Blair Wheadon on SAP Design Studio 1.6

    Blair Wheadon, General Manager, Data Discovery, SAP, joins SAPinsider Studio during the 2015 SAPinsider Reporting & Analytics event in Las Vegas to discuss SAP BusinessObjects Design Studio 1.6 and SAP Cloud for Analytics. This is an edited transcript of the discussion: Ken Murphy, SAPinsider: Hi, this is Ken Murphy with SAPinsider. I am here at…

  5. Live from SAPinsider Studio: Red Hat and Support for the IoT Movement

    Bob Mahoney, Red Hat IoT Business Development,  joins SAPinsider Studio at the 2016 SAPinsider IoT conference to discuss how Red Hat supports the growing IoT movement and community. Topics of this discussion include fundamental use cases of middleware and a joint Red Hat and SAP platform that turns data into actionable intelligence. This is an…

  6. Live from SAPinsider Studio: Invoice-to-Pay with SAP S/4HANA and Ariba

    Friederike Hertenstein, Director, Accounts Payable, SAP Solution Management Finance, visited with SAPinsider Studio at the 2016 SAPinsider Financials event in Las Vegas to discuss Invoice to Pay and Sourcing to Pay processes in SAP S/4HANA Finance and the importance of integrating invoicing with the Ariba Network. This is an edited transcript of the discussion: Ken…

  7. Live from SAPinsider: Ivo Bauermann on the Digital Imperative

    SAPinsider FIN-GRC 2016 keynote speaker Ivo Bauermann, Global Vice President and General Manager, Enterprise Performance Management, SAP, joins SAPinsider Studio at the event to discuss how SAP is helping companies make a digital transformation and run a “live” business. Topics covered include SAP S4/HANA, Central Finance, and Finance’s evolution into a strategic arm of the…

  8. Live from SAPinsider Studio: Paul Ovigele of ERPfixers on S/4HANA and Universal Journal

    Paul Ovigele, founder of ERPfixers, joins SAPinsider Studio at the SAPinsider FIN-GRC event to discuss the impact the Universal Journal in SAP S/4HANA Finance has for reconciling accounts-based vs. costing-based CO-PA tables with the general ledger. This is an edited transcript of the discussion: Ken Murphy, SAPinsider: Hi, this is Ken Murphy with SAPinsider. I…

  9. Live from SAPinsider Studio: O.C. Tanner Rejuvenates its SAP Environment to Keep Up with Customer Needs

    Ethan Kennelly, Director of Enterprise Architecture and Program Management at O.C. Tanner, joins SAPinsider Studio at the SAPinsider SCM-CRM event to discuss how O.C. Tanner’s implementations of SAP Hybris, SAP Configure Price Quote, and SAP S/4HANA helped it to keep up with rapidly changing customer needs. This is an edited transcript of the discussion: Natalie…

  10. Live from SAPinsider Studio: Hans Thalbauer on SAP Leonardo and the Live Business

    Hans Thalbauer, SAP, Senior Vice President, IoT and Digital Supply Chain Solutions, joins SAPinsider’s Ken Murphy to discuss SAP Leonardo at the SAPinsider SCM-IoT-PLM-Manufacturing 2017 event. Ken Murphy, SAPinsider: Hi, this is Ken Murphy with SAPinsider, and I am at the SAPinsider SCM-PLM-Manufacturing-IoT event 2017 in Orlando. This morning, I am pleased to be joined…