Test · TST-Q2-SOD-01
SOD-01 · Segregation of incompatible duties in SAP
FailQ2 2026 Unified Program ReviewTested 18 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.5.3 · ITGC-SOD-01 · RBI-ITGRCA-2023-7.1 · SOC2-CC5.2 · SOC2-CC6.3
mapped
Policy
Payments Security Policy
pol-payments
Control
SOD-01
Segregation of incompatible duties in SAP
Application
SAP S/4HANA
mapped
Evidence · Q3
2 items
2 approved · 0 pending · 0 rejected
Test · Q3
Fail
TST-ITGC-SOD-01 · Medium confidence
Finding
F-RBI-01 · High
In Progress
Action
Priya Sharma
REM-F-RBI-01 · In Progress
Validation
Pending
as recorded
Procedure and result
- Procedure
- SAP GRC Access Risk Analysis ruleset run monthly; mitigating controls documented. Tests: SAP S/4HANA: SoD ruleset — no unmitigated conflicts. Frequency monthly.
- Sample
- 4 items sampled (Q2 baseline)
- Expected
- SAP role design prevents a single user from holding incompatible functions (create vendor / post invoice / release payment / post GL journal); conflicts are detected by a ruleset and either removed or mitigated.
- Observed
- The quarterly SoD ruleset run flagged 4 users holding vendor-master change and payment release; no mitigating control was documented.
- Confidence
- Medium
- Evidence
- Q2-EV-013