“your internal audit sorted” - eohinternational.global · internal audit management lifecycle...

2
“YOUR INTERNAL AUDIT SORTED” SAP | Audit Management SAP GRC Audit Management provide a risk based approach to audit planning. This is achieved by leveraging risk and control information in SAP GRC throughout the planning, creation and execution of audits. Planning Execution Issues & Reporting Create Audit universe & Auditable entities Audit Risk ratings for prioritisation of auditable entities Creation of Audit proposal & Audit plan proposal Schedule of Audit personnel Distribution of Audits based on roles & auditable entities Performance of test criteria and storage of relevant working papers Capture of Audit results Creation of ad-hoc Audit issues Audit plan reporting Audit reports for board & EXCO

Upload: phamphuc

Post on 30-Jul-2019

229 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: “YOUR INTERNAL AUDIT SORTED” - eohinternational.global · Internal Audit Management Lifecycle Universe Creation Planning Prioritisation Issues & Reporting The Audit universe can

“YOUR INTERNAL AUDIT SORTED”

SAP | Audit Management

SAP GRC Audit Management provide a risk based approach to audit planning. This is achieved by leveraging risk and control information in SAP GRC throughout the planning, creation and execution of audits.

Planning Execution Issues & Reporting

Create Audit universe & Auditable entities

Audit Risk ratings for prioritisation of auditable entities

Creation of Audit proposal & Audit plan proposal

Schedule of Audit personnel

Distribution of Audits based on roles & auditable entities

Performance of test criteria and storage of relevant working papers

Capture of Audit results

Creation of ad-hoc Audit issues

Audit plan reporting

Audit reports for board & EXCO

Page 2: “YOUR INTERNAL AUDIT SORTED” - eohinternational.global · Internal Audit Management Lifecycle Universe Creation Planning Prioritisation Issues & Reporting The Audit universe can

Internal Audit Management Lifecycle

UniverseCreation

Planning

Prioritisation

Issues &Reporting

The Audit universe can be structured based on the organisations desired view of relevant data. Organisations can view �nal data by department, function or other logical legal structures that are relevantFollowing the creation of the Auditable entities, data that is relevant can then be utilised from the SAP GRC Risk Management or Process Control modules can be linked

The Audit risk rating is the process used to determine priority of auditable entities according to a set of risk criteria, and to propose audits

An audit proposal is a planned audit for a speci�c auditable entityAn audit plan proposal is a collection of audit proposals grouped into a planned implementation of auditing activities. You create audit plan proposals using new or existing audit proposals

SAP enables you to generate and monitor audit issues using action items from NetWeaver Audit Management and other audit management systemsReports provide information on what risks are applicable to your auditable entities, the planning of your audit, and what auditable entities are applicable to your audit plan proposal

Define auditable entity type

Link data from relevant source to auditable entities

Audit risk rating

Audit proposal Audit plan proposal

Issues Reporting