Test · TST-RBI-SOD-01
SOD-01 · Segregation of incompatible duties in SAP
FailQ3 2026 Unified Program ReviewTested 5 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)
Requirement to validation
Requirement
ISO-A.5.3 · ITGC-SOD-01 · RBI-ITGRCA-2023-7.1 · SOC2-CC5.2 · SOC2-CC6.3
mapped
Policy
Payments Security Policy
pol-payments
Control
SOD-01
Segregation of incompatible duties in SAP
Application
SAP S/4HANA
mapped
Evidence · Q3
2 items
2 approved · 0 pending · 0 rejected
Test · Q3
Fail
TST-ITGC-SOD-01 · Medium confidence
Finding
F-RBI-01 · High
In Progress
Action
Priya Sharma
REM-F-RBI-01 · In Progress
Validation
Pending
as recorded
Procedure and result
- Procedure
- SAP GRC Access Risk Analysis ruleset run monthly; mitigating controls documented. Tests: SAP S/4HANA: SoD ruleset — no unmitigated conflicts. Frequency monthly.
- Sample
- 3 items sampled (reperformance)
- Expected
- SAP role design prevents a single user from holding incompatible functions (create vendor / post invoice / release payment / post GL journal); conflicts are detected by a ruleset and either removed or mitigated.
- Observed
- Access of transferred staff not revoked — SoD breach in payment approval (MD-ITGRCA §7.1).
- Confidence
- Medium
- Evidence
- RBI-REQ-012