Control · P2P-02
Vendor master changes require dual control
Procure-to-PaySOC 2 · ISO 27001 · ITGCRisk High
Requirement to validation
Requirement
ISO-A.5.3 · ITGC-BP-01 · SOC2-CC5.2
mapped
Policy
Payments Security Policy
pol-payments
Control
P2P-02
Vendor master changes require dual control
Application
SAP S/4HANA
mapped
Evidence · Q3
1 items
1 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-ITGC-P2P-02 · High confidence
Finding
None
Action
None
Validation
Not planned
What should be true
Creation of vendors and changes to vendor bank details in SAP are made by Procurement and independently verified by Finance before the vendor can be paid.
- Requirements
- ISO-A.5.3 A.5.3 · Segregation of dutiesITGC-BP-01 ITGC-BP-01 · Automated application controls — approval workflow and thresholdsSOC2-CC5.2 CC5.2 · Selects and develops general controls over technology
- Applications
- SAP S/4HANA
- Third parties
- —
- Testing procedure
- SAP sensitive-field confirmation (FK08/FK09). Tests: SAP S/4HANA: Sensitive vendor fields confirmed by second user. Frequency continuous.
Findings (0)
○ No data available
Evidence (2)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| ITGC-REQ-019 | SAP S/4HANA: Sensitive vendor fields confirmed by second user | P2P-02 | SAP S/4HANA | 8 Oct 2026 | Accepted |
| Q2-EV-015 | SAP S/4HANA · access review (Q2) | P2P-02 | SAP S/4HANA | 6 Jun 2026 | Accepted |
Tests (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-ITGC-P2P-02 | P2P-02 · Vendor master changes require dual control | Q3 2026 Unified Program Review | 7 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit | Pass | High |
| TST-Q2-P2P-02 | P2P-02 · Vendor master changes require dual control | Q2 2026 Unified Program Review | 12 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Pass | High |