Security & GRC
What is Sarbanes-Oxley Act (SOX)?
US law requiring internal controls over financial reporting for public companies, shaping ERP access and change controls.
SOX drives SoD, change management, and IT general controls in SAP. ERP changes need documented testing and approvals. Auditors review test evidence for in-scope changes.
Related terms
Segregation of Duties
A control principle preventing one person from performing conflicting tasks, such as creating suppliers and paying them.
IT General Controls
Baseline controls over access, change management, and operations for systems supporting financial reporting.
Audit Trail
Chronological evidence of who did what and when, used to demonstrate control and compliance.
More in Security & GRC
Planning an S/4HANA move?
Read the field guides on testing an ECC to S/4HANA migration and grab the free template library.