Auditing SAP R/3 – Control Risk Assessment
Peter J. Best · Australian Accounting Review · 2000
This paper provides an introduction to auditing in an SAP R/3 environment, focusing primarily on the assessment of control risk. A number of distinguishing characteristics of the SAP R/3 system that affect the audit are described. The application of a standard internal control framework to the assessment of application controls is illustrated. Two significant pervasive general control areas are examined ‐ system development and program maintenance, and user access control. Relevant controls in these areas are discussed and methods for auditing these controls are outlined. Several opporhcnities for research in the auditing of SAP R/3 are proposed.