The majority of medium‐to‐large international organizations have adopted enterprise resource planning systems (ERPs) of which SAP R/3 is the current market leader. This paper proposes a framework for the separation of duties in SAP R/3. Separation of duties is viewed as a critical component of an organization’s internal control structure aimed primarily at reducing opportunities for fraudulent activities. R/3 assigns profiles consisting of authorizations to users. Accordingly, R/3 facilitates the implementation of “role‐based access control”, where these profiles may be designed consistent with organizational roles and assigned to users performing these roles. This paper proposes a framework for adequate separation of duties using a role‐based approach in the financial accounting (FI) module of the R/3 system. Case studies were undertaken to refine the framework and to explore its application in a practical environment. This empirical research provided support for the adequacy of the proposed framework.
Article navigation
1 July 2003
Case Report|
July 01 2003
A framework for separation of duties in an SAP R/3 environment
Adam Little;
Adam Little
Ernst & Young, Brisbane, Australia
Search for other works by this author on:
Peter J. Best
Peter J. Best
School of Accountancy, Queensland University of Technology, Brisbane, Australia
Search for other works by this author on:
Publisher: Emerald Publishing
Online ISSN: 1758-7735
Print ISSN: 0268-6902
© MCB UP Limited
2003
Managerial Auditing Journal (2003) 18 (5): 419–430.
Citation
Little A, Best PJ (2003), "A framework for separation of duties in an SAP R/3 environment". Managerial Auditing Journal, Vol. 18 No. 5 pp. 419–430, doi: https://doi.org/10.1108/02686900310476882
Download citation file:
New and popular articles
Suggested Reading
Security evaluation of the OAuth 2.0 framework
Information and Computer Security (March,2015)
Security Officers′ Attitudes to the Use of Shared Logons
Information Management & Computer Security (January,1993)
Information flow analysis on role‐based access control model
Information Management & Computer Security (December,2002)
Businesses and Bombs: Preplanning and Response
Management Decision (August,1993)
Child online safety and parental intervention: a study of Sri Lankan internet users
Information Technology & People (May,2018)
Related Chapters
A Comprehensive Set of Introductory Financial Accounting Review Exercises: An Effect to Cause Approach
Advances in Accounting Education: Teaching and Curriculum Innovations
Introduction to Financial Accounting
Financial and Managerial Aspects in Human Resource Management: A Practical Guide
Generative Artificial Intelligence in the Classroom: A Financial Accounting Experience
Advances in Accounting Education: Teaching and Curriculum Innovations
Recommended for you
These recommendations are informed by your reading behaviors and indicated interests.
