Reasonable Assurance Report (ISAE 3000) on the S/4HANA Cloud Edition Authorization Role Concept

The scope of this report includes assurance procedures on the design and implementation as well as the effectiveness of the SAP S/4HANA Cloud Public Edition Authorization Concept of SAP regarding development, design, and implementation to avoid segregation of duty conflicts.

An external auditor has been engaged to perform assurance procedures as a reasonable assurance engagement in accordance with the International Standard on Assurance Engagements 3000 "Assurance Engagements Other Than Audits or Reviews of Historical Financial Information" (ISAE 3000).

In order to gain reasonable assurance evidence, the external auditor decided to assess all relevant processes that influence the quality and usage of the released business catalogs by SAP to customers.

The criteria used for this report were the following Segregation of Duties definitions:

  • “Best Practices to resolve Segregation of Duties conflicts in any Enterprise Resource Planning (ERP) environment” published by the Information Systems Audit and Control Association (ISACA) on December 6th, 2015

  • SAP’s GRC Ruleset (Version 08/2017) as part of the Access Risk Analyses (ARA)

  • Auditor’s Segregation of Duties (SoD) definition

The above-mentioned criteria have been merged to ensure a wide coverage of SoD rules and related risks.