ITGC Audit Checklist for SAP S/4HANA: What Auditors Actually Check

IT General Controls (ITGC) audits are a recurring fact of life for any organization running SAP — whether it’s part of a SOX requirement, an internal audit cycle, or a condition tied to external financing. Yet many teams still approach ITGC audit prep reactively, scrambling to pull evidence together in the weeks before auditors arrive. This checklist covers what auditors actually look for in an SAP S/4HANA environment, and how to stay continuously prepared rather than starting from zero each cycle.

What ITGC audits cover

ITGC audits assess the controls surrounding your IT systems — not the business transactions themselves, but the environment those transactions run in. For SAP specifically, this typically breaks down into four control areas:

Access controls — Who can get into the system, and what can they do once they’re in? Auditors check user provisioning and deprovisioning processes, role assignment logic, and segregation of duties (SoD) between conflicting functions.

Change management — How are changes to SAP configuration, custom code, and transport requests approved, tested, and moved into production? Auditors want evidence of a controlled, documented change path — not ad hoc production changes.

Computer operations — Are batch jobs, interfaces, and backups monitored and functioning as expected? This covers the operational reliability of the system itself.

Program development — For custom SAP development, is there a controlled software development lifecycle with appropriate testing and approval gates before code reaches production?

The checklist: what to have ready

User access and provisioning

  • Documented process for granting, modifying, and revoking SAP access
  • Evidence that access requests go through a formal approval workflow
  • Termination/role-change checklist showing access is revoked or adjusted promptly
  • Periodic user access review (UAR) records — not just that reviews happened, but that flagged issues were remediated

Segregation of duties

  • A defined SoD risk matrix specific to your business processes
  • Evidence of regular SoD conflict analysis, not just a one-time assessment
  • Documentation of compensating controls for any accepted/unavoidable conflicts
  • A remediation trail showing how identified violations were resolved

Privileged and emergency access

  • Firefighter/emergency access request and approval records
  • Logs showing what actions were taken during each emergency access session
  • Evidence that elevated access was time-bound and revoked automatically
  • Review of firefighter log activity against what was originally requested

Change management

  • Transport request approval trail from development through production
  • Evidence of testing prior to production deployment
  • Segregation between who develops, who approves, and who moves transports to production
  • Emergency change process documentation, separate from standard change flow

System configuration and monitoring

  • Records of sensitive configuration changes (e.g., changes to critical authorization objects)
  • Monitoring evidence for critical/sensitive transactions
  • Alerting configuration for high-risk activity

Reporting readiness

  • Ability to produce access reports, SoD violation reports, and change logs on demand — not reconstructed manually when the audit request comes in
  • Historical reporting that shows control operation over the full audit period, not just a point-in-time snapshot

Why manual preparation falls short

The pattern that causes the most audit friction is treating ITGC evidence as something to assemble right before the audit, rather than something that’s continuously available. Manually pulling access reports, cross-referencing SoD conflicts, and reconstructing change logs from multiple systems is slow, prone to gaps, and makes it hard to demonstrate that controls operated consistently across the entire period under review — which is what auditors are actually testing for.

How SimpAudit supports ITGC readiness

SimpAudit is built to keep this evidence continuously ready rather than reconstructed under deadline pressure. Running natively inside SAP, it provides real-time SoD violation tracking against a library of 2,000+ predefined risks, drill-down visibility into affected users, roles, and transactions, and audit-ready SOX and ITGC reports that can be generated on demand rather than assembled by hand. Role changes, sensitive transaction activity, and privileged access are monitored continuously, with heatmaps and dashboards that give both IT and audit teams a shared, real-time view of control health — well before the auditors show up.

Preparing for your next ITGC cycle