SAP SOX Compliance


What Is SOX Compliance?

The Sarbanes-Oxley Act (SOX) of 2002 requires financial transparency by U.S. public companies, ensuring their data is secure and accurate. Drafted by Congressmen Paul Sarbanes and Michael Oxley following several U.S. corporate and financial scandals, SOX compliance means having a formalized system for internal controls — one that provides full financial transparency.

In a blog post, the criticality of SAP governance, risk management, and compliance (GRC) for SOX compliance is explored. The author points out that two sections (Section 302 and Section 404) are the most important and relevant for SAP GRC and finance users.

What Is SOX Compliance?

The Sarbanes-Oxley Act (SOX) of 2002 requires financial transparency by U.S. public companies, ensuring their data is secure and accurate. Drafted by Congressmen Paul Sarbanes and Michael Oxley following several U.S. corporate and financial scandals, SOX compliance means having a formalized system for internal controls — one that provides full financial transparency.

In a blog post, the criticality of SAP governance, risk management, and compliance (GRC) for SOX compliance is explored. The author points out that two sections (Section 302 and Section 404) are the most important and relevant for SAP GRC and finance users.

An SAP SOX compliance checklist should address the following:

  • Segregation of duties
  • SAP GRC monitoring
  • Safeguard SOX audit trails against emergency access
  • Automate SAP audit reporting

Further Resources for SAPinsiders

Accounting & Finance Expands Its Influence. In this article, learn how UGI Utilities developed a strategic roadmap to better anticipate internal and external demands on the business — including regulations such as SOX. The utility shares how using BlackLine and its task functionality provides intuitive controls for SOX compliance.

Beyond SOX: Addressing non-financial risks through SAP configuration and sound supporting processes. Often, compliance is a focal point during SAP implementation to ensure compliance with financial reporting and regulations, such as SOX. However, there are optional SAP controls that could provide even more value to companies’ SAP system and supporting processes. In this session, Steve Biskie from RSM shares how to minimize and mitigate operational and strategic risks through SAP configuration. Understand who in the organization should be involved in recommending and validating control changes, and how to set up an appropriate cross-functional team to ensure decisions are sound and don’t introduce other risks.

Bridging the Cybersecurity Gap in IT General Controls (ITGC). Compliance with regulations like SOX often require a set of controls in place to mitigate risks to the integrity of financial reporting. Current ITGC testing performed by internal and external auditors is only focused on one slice of access risk. In this session, Brian Tremblay from Onapsis shares why it’s critical to understand the threats that exist to your SAP system beyond the current ITGC scope and how they relate to compliance with SOX.

 

A vendor that can help SAP customers with SOX compliance is Appsian Security. The provider offers a single platform for automating how users secure user identity, govern access, detect and prevent fraud, and demonstrate compliance with SOX, the General Data Protection Regulation, and more across critical business applications.  

969 results

  1. Live from SAPinsider Studio: Richard Howells on Harnessing the Internet of Things

    Richard Howells, Global Vice President of Extended Supply Chain at SAP, joins SAPinsider Studio at the SAPinsider SCM-CRM 2016 event to discuss how the Internet of Things can help organizations re-imagine their supply chains. This is an edited transcript of the discussion: Natalie Miller, SAPinsider: Hi, I’m Natalie Miller with SAPinsider, and I’m here at…

  2. Live from SAPinsider Studio: Mike Lackey on the Evolving Nature of Manufacturing

    Mike Lackey, Global VP of Solution Management for LoB Manufacturing at SAP, joins SAPinsider Studio at the SAP SCM 2016 event to discuss how IoT and digital business is transforming the nature of manufacturing. Natalie Miller, SAPinsider: Hi, I’m Natalie Miller with SAPinsider and we’re at the SCM, CRM, and IoT event in Las Vegas…

  3. Live from SAPinsider Studio: Volker Hildebrand on Going Beyond CRM

    Volker Hildebrand, Global VP of Customer Engagement and Commerce at SAP Hybris, joins SAPinsider Studio at CRM 2016 to discuss how digital disruptions and evolving technologies are pushing businesses to move beyond traditional CRM practices. Natalie Miller, SAPinsider: Hi, I’m Natalie Miller with SAPinsider, and we’re here at the SCM, CRM, and IoT event in…

  4. SAPPHIRE NOW has SAP HANA Platform Content Covered

    Published: 03/May/2016

    Reading time: 3 mins

    How important to the SAP roadmap is SAP HANA as a platform for analytics and enterprise data warehousing? A quick search of the SAPPHIRE NOW and ASUG Annual Conference agenda – the co-located events begin May 17 in Orlando, Florida – provides a hint. In total, that search yields 555 sessions in the Digital Enterprise…

  5. New Horizons: An Outline of the SAPinsider Digital Supply Management New Research Approach

    Published: 29/January/2019

    Reading time: 2 mins

    I’m reading a book titled The Barons of the Sea, which is an account of the 19th century merchants and trading companies that battled for supremacy in importing tea from China in exchange for shipments of opium. The goal of these entrepreneurs was to find a way to shorten a traditional six-month journey from China…

  6. Bill McDermott Leaves CEO Position at SAP: Impact for SAPinsiders

    Published: 11/October/2019

    Reading time: 4 mins

    SAP CEO Bill McDermott announced yesterday that effective immediately he is stepping down from the helm of the German software company after nine years on the job. During his near-decade leading SAP, McDermott steered SAP in several significant ways. The company began its transition to its cloud, snapping up over $20 billion of acquisitions while…

  7. Simple Ways to Get Started on Your SAP S/4HANA Journey

    Published: 31/October/2019

    Reading time: 6 mins

    Moving to SAP S/4HANA is the No. 1 project on the minds of SAP customers. As the 2025 deadline approaches, organizations find themselves at least in the evaluation and fact-finding stage of the project. SAPinsider had the opportunity to sit down with Sven Denecken, Senior Vice President of Product Management, Co-Innovation SAP S/4HANA at SAP…

  8. ABAP for the Modern Age

    Published: 14/January/2016

    Reading time: 15 mins

    Some of the most significant innovations in SAP NetWeaver 7.5 — the latest iteration of SAP’s well-known technology and integration platform — are in the ABAP programming model. This article looks at a set of particularly useful features available with ABAP 7.5, including new ABAP language features for enabling more concise code and enhancements that…

  9. Six Reasons Why You Should Attend the SAPinsider 2020 Conference in Las Vegas

    Published: 12/January/2020

    Reading time: 2 mins

    Members of the SAP community are looking forward to a transformative 2020 which promises to be both an exhilerating and challenging time. As you weigh your business’ move to SAP S/4HANA, the Cloud, and emerging technologies such as Artificial Intelligence and Blockchain, SAPinsider is here for you as a trusted resource. If you don’t have…

  10. Trends in SAP S/4HANA Cloud Usage – A Benchmark Study

    Published: 20/February/2020

    Reading time: 2 mins

    Even with the extension of mainstream maintenance for existing SAP ERP systems to 2027, the topic of SAP S/4HANA migration is still a critical one for most SAP ERP customers. This is not only because the migration process can require a significant time and resource investment, but also because many customers are now leveraging the…