GDPR & SAP: Implementing Data Protection in SAP Systems
GDPR requirements in SAP: identify data, deletion concept and data subject rights.
Read more →
An SAP audit is approaching – for many IT teams a cause for anxiety. It need not be: with systematic preparation and good documentation, the review becomes routine rather than a stress factor. This article provides a field-tested checklist for audit preparation.
First understand which audit type is pending: internal audit checks compliance with internal policies. External auditors focus on financial statement-relevant IT controls (SOX/ITGC). ISO 27001 auditors assess the information security management system. Clarify the audit scope early with the auditors – this allows you to target your preparation.
Regardless of audit type, the following areas are almost always examined:
Conduct a self-assessment 6–8 weeks before the audit: check all controls against expected requirements. Identify weaknesses and remediate them before the audit. Ensure all evidence is available and current. Walk through critical processes once (e.g. emergency user activation, transport workflow). The self-assessment is your chance to avoid findings before the auditor discovers them.
Auditors assess based on evidence. Prepare the following documents: user lists with roles and last logon date (SUIM reports), SoD analysis results with risk assessment and measures, transport logs with change ticket assignment, patch status overview (installed security notes, open notes with justification), backup logs and recovery test reports, emergency user usage logs with controller confirmation and policy documents (authorisation concept, emergency concept, patch policy). Present evidence in a structured manner – a well-prepared audit folder saves time for everyone involved.
The top 5 findings in SAP audits:
Designate a single point of contact for the auditor. Answer questions precisely and completely – but do not voluntarily reveal additional problem areas. Deliver requested evidence promptly. Document all discussions and requirements. For unclear questions, ask for clarification rather than speculating.
The best audit preparation is a well-functioning IT operation with clean documentation. If you continuously implement the points described here, every audit becomes routine. Start preparation early and use the self-assessment as a quality check.
GDPR requirements in SAP: identify data, deletion concept and data subject rights.
Read more →Systematically detect and pragmatically resolve SoD conflicts.
Read more →10 measures for secure SAP systems.
Read more →We help you with implementation – from analysis to go-live.
Get in touch