Test · TST-RBI-SOD-01

SOD-01 · Segregation of incompatible duties in SAP

FailQ3 2026 Unified Program ReviewTested 5 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)

Requirement to validation

Procedure and result

Procedure
SAP GRC Access Risk Analysis ruleset run monthly; mitigating controls documented. Tests: SAP S/4HANA: SoD ruleset — no unmitigated conflicts. Frequency monthly.
Sample
3 items sampled (reperformance)
Expected
SAP role design prevents a single user from holding incompatible functions (create vendor / post invoice / release payment / post GL journal); conflicts are detected by a ruleset and either removed or mitigated.
Observed
Access of transferred staff not revoked — SoD breach in payment approval (MD-ITGRCA §7.1).
Confidence
Medium
Evidence
RBI-REQ-012