{"id":11463,"date":"2016-11-30T15:00:00","date_gmt":"2016-11-30T15:00:00","guid":{"rendered":"https:\/\/zapliance.com\/?p=11463"},"modified":"2022-08-26T14:19:44","modified_gmt":"2022-08-26T14:19:44","slug":"proper-protection-of-vendor-master-data","status":"publish","type":"post","link":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/","title":{"rendered":"Proper protection of vendor master data"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Part II&nbsp;of the series: \u201cAutomated Audit of the Configuration and Authorizations in SAP MM\u201d<\/h2>\n\n\n\n<p>Today\u2019s blog post presents you with three audit procedures for auditing authorizations of vendor master data.<\/p>\n\n\n\n<p>1.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/is-everything-well-organized-auditing-organizational-structures-in-sap-mm?lang=en\">Is everything well organized? Auditing organizational structures in SAP MM<\/a><br><strong>2. Proper protection of vendor master data<\/strong><br>3.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/the-procedure-for-checking-the-approval-process-for-purchase-requisitions?lang=en\">The procedure for checking the approval process for purchase requisitions<\/a><br>4.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/are-your-purchase-orders-ordered-in-the-best-way?lang=en\">Are your purchase orders ordered in the best way?<\/a><br>5.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/everything-under-control-for-critical-goods-movements?lang=en\">Everything under control for critical goods movements<\/a><br>6.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/how-to-protect-your-invoice-verification?lang=en\">How to protect your invoice verification<\/a><br>7.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/clear-interrelationships-when-recording-the-physical-inventory?lang=en\">Clear interrelationships when recording the physical inventory<\/a><br>8.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/customizing-in-sap-mm-set-at-the-test-bench?lang=en\">Customizing in SAP MM set at the test bench<\/a><br>9.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/segregation-of-duties-in-purchase-to-pay?lang=en\">Segregation of duties in&nbsp;\u201cpurchase to pay\u201d<\/a><br>10.&nbsp;<a href=\"https:\/\/zapliance.com\/blog\/good-practices-in-relation-to-the-segregation-of-duties-between-purchase-to-pay-and-financial-accounting?lang=en\">Good practices in relation to the segregation&nbsp;of duties between&nbsp;\u201cpurchase to pay\u201d and \u201cfinancial accounting\u201d<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Separation of SAP master data maintenance in Purchasing and in Financial Accounting<\/h2>\n\n\n\n<p>Vendor master data can be maintained in both purchasing and financial accounting. The difference is that no company code-specific data is allowed to be maintained in purchasing and that no purchasing-specific data is allowed to be maintained in financial accounting. Likewise, maintenance of bank details is reserved for financial accounting. In terms of authorizations, this can be mapped by using different transactions (FK*, MK*, XK*).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Four-eyes principle when maintaining sensitive data<\/h2>\n\n\n\n<p>When maintaining the vendor master data of a large number of users, there is often a need to implement a four-eyes principle for sensitive fields (such as bank details, for example). After a change is made, a different user has to check and approve the change. Sensitive fields can be defined for this purpose in customizing. If one of these fields is changed, the vendor is automatically locked for payments. The lock must be released by a different user (asymmetrical four-eyes&nbsp;principle). If no four-eyes&nbsp;principle is in place, payment-related vendor master data may be changed, which may result in payments to this vendor being redirected to a different account, for example.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Individual authorization for maintaining sensitive data<\/h2>\n\n\n\n<p>In addition to an asymmetrical four-eyes&nbsp;principle, there is also the option of explicitly allowing only specific users to change sensitive fields. Maintenance of these fields is then blocked for all other users that are generally permitted to maintain vendors. These fields must be defined in customizing.<\/p>\n\n\n\n<p>You can download the details about all SAP settings here:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/2492072\/1c223804-2774-4c09-b4fc-e8025ed9466e\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/2492072\/1c223804-2774-4c09-b4fc-e8025ed9466e.png\" alt=\"Download pdf\"\/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Part II&nbsp;of the series: \u201cAutomated Audit of the Configuration and Authorizations in SAP MM\u201d Today\u2019s blog post presents you with three audit procedures for auditing authorizations of vendor master data. 1.&nbsp;Is everything well organized? Auditing organizational structures in SAP MM2. Proper protection of vendor master data3.&nbsp;The procedure for checking the approval process for purchase requisitions4.&nbsp;Are [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":10699,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[38,37,40],"tags":[],"class_list":["post-11463","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-en-audit","category-en-compliance","category-en-finance"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Proper protection of vendor master data - zapliance<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Proper protection of vendor master data - zapliance\" \/>\n<meta property=\"og:description\" content=\"Part II&nbsp;of the series: \u201cAutomated Audit of the Configuration and Authorizations in SAP MM\u201d Today\u2019s blog post presents you with three audit procedures for auditing authorizations of vendor master data. 1.&nbsp;Is everything well organized? Auditing organizational structures in SAP MM2. Proper protection of vendor master data3.&nbsp;The procedure for checking the approval process for purchase requisitions4.&nbsp;Are [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/\" \/>\n<meta property=\"og:site_name\" content=\"zapliance\" \/>\n<meta property=\"article:published_time\" content=\"2016-11-30T15:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-08-26T14:19:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2400\" \/>\n\t<meta property=\"og:image:height\" content=\"962\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Thomas Tiede\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Thomas Tiede\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/\"},\"author\":{\"name\":\"Thomas Tiede\",\"@id\":\"https:\/\/zapliance.com\/en\/#\/schema\/person\/0e3ca2af4e2fa9dd840ecf56e05af1a3\"},\"headline\":\"Proper protection of vendor master data\",\"datePublished\":\"2016-11-30T15:00:00+00:00\",\"dateModified\":\"2022-08-26T14:19:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/\"},\"wordCount\":399,\"publisher\":{\"@id\":\"https:\/\/zapliance.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png\",\"articleSection\":[\"Audit\",\"Compliance\",\"Finance\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/\",\"url\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/\",\"name\":\"Proper protection of vendor master data - zapliance\",\"isPartOf\":{\"@id\":\"https:\/\/zapliance.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png\",\"datePublished\":\"2016-11-30T15:00:00+00:00\",\"dateModified\":\"2022-08-26T14:19:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage\",\"url\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png\",\"contentUrl\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png\",\"width\":2400,\"height\":962},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\/\/zapliance.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Proper protection of vendor master data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zapliance.com\/en\/#website\",\"url\":\"https:\/\/zapliance.com\/en\/\",\"name\":\"zapliance\",\"description\":\"Be the agent of change\",\"publisher\":{\"@id\":\"https:\/\/zapliance.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zapliance.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/zapliance.com\/en\/#organization\",\"name\":\"zapliance\",\"url\":\"https:\/\/zapliance.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zapliance.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/06\/zap_logo.svg\",\"contentUrl\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/06\/zap_logo.svg\",\"width\":200,\"height\":45,\"caption\":\"zapliance\"},\"image\":{\"@id\":\"https:\/\/zapliance.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/zapliance.com\/en\/#\/schema\/person\/0e3ca2af4e2fa9dd840ecf56e05af1a3\",\"name\":\"Thomas Tiede\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zapliance.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/avatar_user_13_1661960960-96x96.png\",\"contentUrl\":\"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/avatar_user_13_1661960960-96x96.png\",\"caption\":\"Thomas Tiede\"},\"description\":\"Managing Director IBS Schreiber GmbH\",\"url\":\"https:\/\/zapliance.com\/en\/blog\/author\/thomas-tiede\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Proper protection of vendor master data - zapliance","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/","og_locale":"en_US","og_type":"article","og_title":"Proper protection of vendor master data - zapliance","og_description":"Part II&nbsp;of the series: \u201cAutomated Audit of the Configuration and Authorizations in SAP MM\u201d Today\u2019s blog post presents you with three audit procedures for auditing authorizations of vendor master data. 1.&nbsp;Is everything well organized? Auditing organizational structures in SAP MM2. Proper protection of vendor master data3.&nbsp;The procedure for checking the approval process for purchase requisitions4.&nbsp;Are [&hellip;]","og_url":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/","og_site_name":"zapliance","article_published_time":"2016-11-30T15:00:00+00:00","article_modified_time":"2022-08-26T14:19:44+00:00","og_image":[{"width":2400,"height":962,"url":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png","type":"image\/png"}],"author":"Thomas Tiede","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Thomas Tiede","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#article","isPartOf":{"@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/"},"author":{"name":"Thomas Tiede","@id":"https:\/\/zapliance.com\/en\/#\/schema\/person\/0e3ca2af4e2fa9dd840ecf56e05af1a3"},"headline":"Proper protection of vendor master data","datePublished":"2016-11-30T15:00:00+00:00","dateModified":"2022-08-26T14:19:44+00:00","mainEntityOfPage":{"@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/"},"wordCount":399,"publisher":{"@id":"https:\/\/zapliance.com\/en\/#organization"},"image":{"@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage"},"thumbnailUrl":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png","articleSection":["Audit","Compliance","Finance"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/","url":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/","name":"Proper protection of vendor master data - zapliance","isPartOf":{"@id":"https:\/\/zapliance.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage"},"image":{"@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage"},"thumbnailUrl":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png","datePublished":"2016-11-30T15:00:00+00:00","dateModified":"2022-08-26T14:19:44+00:00","breadcrumb":{"@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#primaryimage","url":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png","contentUrl":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/Blog-Dummy.png","width":2400,"height":962},{"@type":"BreadcrumbList","@id":"https:\/\/zapliance.com\/en\/blog\/proper-protection-of-vendor-master-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/zapliance.com\/en\/"},{"@type":"ListItem","position":2,"name":"Proper protection of vendor master data"}]},{"@type":"WebSite","@id":"https:\/\/zapliance.com\/en\/#website","url":"https:\/\/zapliance.com\/en\/","name":"zapliance","description":"Be the agent of change","publisher":{"@id":"https:\/\/zapliance.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zapliance.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zapliance.com\/en\/#organization","name":"zapliance","url":"https:\/\/zapliance.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zapliance.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/06\/zap_logo.svg","contentUrl":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/06\/zap_logo.svg","width":200,"height":45,"caption":"zapliance"},"image":{"@id":"https:\/\/zapliance.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zapliance.com\/en\/#\/schema\/person\/0e3ca2af4e2fa9dd840ecf56e05af1a3","name":"Thomas Tiede","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zapliance.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/avatar_user_13_1661960960-96x96.png","contentUrl":"https:\/\/zapliance.com\/wp-content\/uploads\/2022\/08\/avatar_user_13_1661960960-96x96.png","caption":"Thomas Tiede"},"description":"Managing Director IBS Schreiber GmbH","url":"https:\/\/zapliance.com\/en\/blog\/author\/thomas-tiede\/"}]}},"views":1530,"_links":{"self":[{"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/posts\/11463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/comments?post=11463"}],"version-history":[{"count":1,"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/posts\/11463\/revisions"}],"predecessor-version":[{"id":11464,"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/posts\/11463\/revisions\/11464"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/media\/10699"}],"wp:attachment":[{"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/media?parent=11463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/categories?post=11463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zapliance.com\/en\/wp-json\/wp\/v2\/tags?post=11463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}