CORAA
Blog/Internal Audit

SAP Tables for Internal Audit (2026): The Data Request, Cycle by Cycle

SAP tables for audit in 2026, cycle by cycle: procure-to-pay, order-to-cash, record-to-report, fixed assets, inventory, payroll and user access, with key fields, how to word the request, ECC versus S/4HANA differences, Tally equivalents and the mistakes that waste a week.

CCORAA Team1 October 202612 min read

The SAP tables an internal audit normally asks for are BKPF and BSEG for accounting documents (ACDOCA in S/4HANA), LFA1, LFB1 and LFBK for vendors, EKKO, EKPO and EKBE for purchase orders, RBKP and RSEG for vendor invoices, REGUH and REGUP for payment runs, KNA1, VBAK, LIKP and VBRK for customers and sales, ANLA and ANLC for assets, MARA, MBEW and the material documents for inventory, and USR02, AGR_USERS, CDHDR and CDPOS for access and changes. Ask for each as a table extract for a stated company code and period, header and line tables together, with a row count and a control total you can agree to the trial balance.

The slowest part of an audit on SAP is usually the request itself: the audit team asks for "the vendor ledger", the SAP team asks "which table?", and a fortnight passes. This guide gives the request cycle by cycle, for the head of internal audit or finance controller who has to word it and the SAP team who has to run it.

Start here if you want the working file:

Need Use this
A request list in Excel for the cycles you pick, ECC or S/4HANA, with period, company code, format and owner columns SAP Tables for Audit: Data Request Builder
A request list by process cycle for any accounting system Internal Audit Data Request List
Checks to run before relying on any extract Source data readiness guide

A note before the tables: everything below uses standard, long-established SAP names. Table availability differs between ECC and S/4HANA, custom fields (names beginning with Z or Y) and archiving differ from one installation to the next, and your SAP team should confirm each table for the release in use.

How to ask

A request that gets answered in one pass states six things.

  1. Period. By posting date for documents. Master data and access tables as at the extraction date.
  2. Company code. Name them. No other filter — not by document type, not by user, not by plant.
  3. Production client only.
  4. Format. One file per table, field names in the first row, dates and amounts unformatted. Delimited text for large line-item tables, which often exceed the row limit of a spreadsheet.
  5. Header and line tables together. A header table without its items gives you dates and users but no amounts; items without the header give amounts but no document type or posting date.
  6. Change logs with the masters. The vendor master as it stands today does not show that a bank account was changed for a week in June. The change documents do.

And for every file: the selection screen used, the row count per SAP, and a total you can tie back.

Procure-to-pay

Table What it holds Key fields
LFA1 Vendor master — general data LIFNR, NAME1, ERDAT, ERNAM, SPERR, LOEVM
LFB1 Vendor master — company code data LIFNR, BUKRS, AKONT, ZTERM, ZWELS, REPRF
LFBK Vendor bank details LIFNR, BANKS, BANKL, BANKN
EKKO / EKPO Purchase order — header and items EBELN, BSART, LIFNR, BEDAT, ERNAM, FRGKE / EBELN, EBELP, MATNR, MENGE, NETPR, NETWR
EKBE Purchase order history — receipts and invoices against each line EBELN, EBELP, VGABE, BELNR, BUDAT, MENGE, DMBTR
RBKP / RSEG Vendor invoice posted through purchasing — header and items BELNR, GJAHR, LIFNR, XBLNR, BLDAT, RMWWR, STBLG / BELNR, EBELN, EBELP, MENGE, WRBTR
BSIK / BSAK Vendor open items / cleared items LIFNR, BELNR, XBLNR, WRBTR, SHKZG, UMSKZ, AUGBL, AUGDT
REGUH / REGUP Payment run — payments and the invoices in each LAUFD, LAUFI, LIFNR, VBLNR, RWBTR / LAUFD, LAUFI, BELNR, XBLNR
PAYR Cheque register, where cheques are issued from SAP CHECT, HBKID, VBLNR, LIFNR, RWBTR

These support the three-way match line by line, vendors created and paid in the same period, bank accounts shared between vendors, orders raised after the invoice date, and duplicate payment tests. Where PAN and GSTIN are stored depends on the India localisation and the release, so ask for "vendor PAN and GSTIN" by description rather than by field name.

Order-to-cash

Table What it holds Key fields
KNA1 / KNB1 Customer master — general and company code data KUNNR, NAME1, ERDAT, ERNAM, SPERR / KUNNR, BUKRS, AKONT, ZTERM
VBAK / VBAP Sales order — header and items VBELN, ERDAT, AUART, KUNNR, NETWR / VBELN, POSNR, MATNR, KWMENG, NETWR, ABGRU
LIKP / LIPS Delivery — header and items VBELN, KUNNR, LFDAT, WADAT_IST / VBELN, POSNR, MATNR, LFIMG, VGBEL
VBRK / VBRP Billing document — header and items VBELN, FKART, FKDAT, KUNRG, NETWR, FKSTO / VBELN, POSNR, MATNR, FKIMG, NETWR, AUBEL
VBFA Sales document flow VBELV, POSNV, VBELN, POSNN, VBTYP_N
BSID / BSAD Customer open items / cleared items KUNNR, BELNR, XBLNR, BLDAT, ZFBDT, WRBTR, SHKZG, AUGBL, AUGDT

These support cut-off testing (goods issued before the period end and billed after), deliveries not billed, cancelled invoices and credit notes, selling price by customer, and receivables ageing. Credit limits are held differently in ECC and S/4HANA; ask for "customer credit limits and exposure" as a report.

Record-to-report

Table What it holds Key fields
BKPF Accounting document — header BUKRS, BELNR, GJAHR, BLART, BLDAT, BUDAT, CPUDT, USNAM, TCODE, XBLNR, STBLG
BSEG Accounting document — line items BUKRS, BELNR, GJAHR, BUZEI, KOART, SHKZG, HKONT, DMBTR, SGTXT, LIFNR, KUNNR
ACDOCA (S/4HANA) Universal Journal — every line item, all ledgers RLDNR, RBUKRS, GJAHR, BELNR, DOCLN, RACCT, HSL, BUDAT, BLART, USNAM
FAGLFLEXA (ECC, new general ledger) General ledger line items by ledger RLDNR, RBUKRS, RYEAR, DOCNR, RACCT, HSL, PRCTR
GLT0 or FAGLFLEXT General ledger totals — classic or new general ledger RBUKRS / BUKRS, RYEAR, RACCT, HSLVT, HSL01 to HSL16
BSIS / BSAS G/L account open items / cleared items BUKRS, HKONT, BELNR, BUDAT, DMBTR, SHKZG, AUGDT
SKA1 / SKB1 / SKAT Chart of accounts, company code settings, account names KTOPL, SAKNR, XBILK / BUKRS, SAKNR, XSPEB / SAKNR, TXT50
T001 Company codes BUKRS, BUTXT, WAERS, KTOPL
T001B Posting periods open, by account type MKOAR, FRYE1, FRPE1, TOYE1, TOPE1

This is the journal-testing population: back-dated entries (entry date against posting date), entries by user, manual document types, reversals, and old open items on suspense and clearing accounts. Document type (BLART) is what separates a manual journal from a system posting — never leave it out.

Fixed assets

Table What it holds Key fields
ANLA Asset master BUKRS, ANLN1, ANLN2, ANLKL, TXT50, AKTIV, DEAKT
ANLZ Time-dependent assignments ANLN1, ANLN2, BDATU, ADATU, KOSTL, WERKS, STORT
ANLB Depreciation terms by depreciation area ANLN1, ANLN2, AFABE, AFASL, NDJAR, NDPER, AFABG
ANLC Asset values by year and depreciation area ANLN1, ANLN2, GJAHR, AFABE, KANSW, KNAFA, NAFAG
ANEP Asset line items — additions, transfers, retirements ANLN1, ANLN2, GJAHR, LNRAN, BWASL, ANBTR, BZDAT

Ask for the capital work-in-progress ageing as a report; it is often tracked through internal orders or projects as well.

Inventory

Table What it holds Key fields
MARA Material master — general data MATNR, MTART, MATKL, MEINS, ERSDA, LVORM
MARD Stock by plant and storage location MATNR, WERKS, LGORT, LABST, INSME, SPEME
MBEW Material valuation MATNR, BWKEY, BKLAS, VPRSV, VERPR, STPRS, LBKUM, SALK3
MCHB Batch stock MATNR, WERKS, LGORT, CHARG, CLABST
MKPF / MSEG (ECC) Material documents — header and items MBLNR, MJAHR, BUDAT, USNAM / MBLNR, ZEILE, BWART, MATNR, WERKS, MENGE, DMBTR
MATDOC (S/4HANA) Material documents — header and items in one table MBLNR, MJAHR, ZEILE, BUDAT, BWART, MATNR, WERKS, MENGE, DMBTR
IKPF / ISEG Physical inventory documents IBLNR, GJAHR, WERKS, LGORT / IBLNR, MATNR, MENGE, BUCHM

Payroll and HR

Table What it holds Key fields
PA0000 Personnel actions — joiners and leavers PERNR, BEGDA, ENDDA, MASSN, STAT2
PA0001 Organisational assignment PERNR, BEGDA, ENDDA, BUKRS, WERKS, KOSTL
PA0002 Personal data PERNR, NACHN, VORNA, GBDAT
PA0008 Basic pay PERNR, BEGDA, ENDDA, TRFGR, LGA01, BET01
PA0009 Bank details PERNR, BEGDA, ENDDA, BANKL, BANKN
PA0014 / PA0015 Recurring and one-off payments and deductions PERNR, BEGDA, LGART, BETRG

Payroll results are stored in clusters, not ordinary tables, and are normally requested as a wage-type report by employee and month. Many companies run payroll outside SAP; then the request goes to the payroll provider. Employee data is personal data — ask only for the fields the test needs, and agree how the files will be stored and when they will be deleted.

User access and change logs

Table What it holds Key fields
USR02 User logon data BNAME, USTYP, GLTGV, GLTGB, TRDAT, UFLAG
AGR_USERS Roles assigned to users AGR_NAME, UNAME, FROM_DAT, TO_DAT
AGR_1251 Authorisation values in each role AGR_NAME, OBJECT, FIELD, LOW, HIGH
AGR_DEFINE Role definitions AGR_NAME, PARENT_AGR
UST04 Profiles assigned to users BNAME, PROFILE
CDHDR / CDPOS Change documents — header and items OBJECTCLAS, OBJECTID, CHANGENR, USERNAME, UDATE, TCODE / TABNAME, FNAME, CHNGIND, VALUE_OLD, VALUE_NEW
E070 / E071 Transport requests and the objects in them TRKORR, TRFUNCTION, TRSTATUS, AS4USER, AS4DATE / TRKORR, OBJECT, OBJ_NAME
DBTABLOG Table change log, where logging is switched on TABNAME, LOGDATE, USERNAME

CDPOS is large; request it by change object and date range. The security audit log is kept only if it has been switched on, and is requested as a report for the period.

ECC versus S/4HANA: what changes in the request

Area SAP ECC SAP S/4HANA
General ledger line items BKPF with BSEG; FAGLFLEXA where the new general ledger is active ACDOCA is the complete line-item source. BSEG is still written for finance postings but no longer holds every line
General ledger totals GLT0 or FAGLFLEXT Totals are calculated from ACDOCA; request the trial balance report and agree it to the sum of the extract
Open and cleared items BSIS/BSAS, BSIK/BSAK, BSID/BSAD Readable as compatibility views; the line items are in ACDOCA
Material documents MKPF and MSEG MATDOC; the older tables remain readable as compatibility views
Asset values and line items ANLC, ANEP Compatibility views; values are held in ACDOCA. Ask for the asset history sheet alongside
Vendors and customers LFA1, KNA1 and related tables Still filled, but maintained as business partners (BUT000), linked through CVI_VEND_LINK and CVI_CUST_LINK; bank details sit in BUT0BK

Two practical points. In ECC, BSEG is a cluster table and cannot always be extracted in the ordinary way; many teams take the open and cleared item tables instead, which together give the same line items. In S/4HANA, ACDOCA holds a line for each ledger, so state the leading ledger in the request — otherwise every amount is counted more than once.

The Tally equivalent, for groups that run both

Many groups have the larger entities on SAP and the smaller ones on Tally. The audit needs the same information from both.

Cycle Ask the Tally entity for
Procure-to-pay Ledgers under Sundry Creditors with PAN, GSTIN and bank details; Purchase Register with supplier invoice number and date; Receipt Note Register and Purchase Order Book where used; Payment Register; bill-wise outstandings for payables
Order-to-cash Ledgers under Sundry Debtors; Sales Register and Credit Note Register; Delivery Note Register and Sales Order Book where used; Receipt Register; bill-wise outstandings for receivables
Record-to-report Day Book for the period, all voucher types, with voucher number, ledgers, amount and narration; Trial Balance, opening and closing; Journal Register; List of Accounts
Fixed assets Ledger vouchers under the Fixed Assets group; the asset register kept outside Tally; the depreciation working
Inventory Stock Summary with the godown-wise view; Stock Journal Register; Physical Stock Register where used; stock ageing analysis
Payroll Pay Sheet and Payroll Register where Tally payroll is used; otherwise the salary journal and bank advice
Access and changes Users and security levels; the edit log of altered and deleted vouchers and masters, where enabled

Report and column names depend on the Tally version and on which features are switched on.

Worked example: a filled request line

Illustrative only — one line from a procure-to-pay request for the first half of FY 2026-27.

Field Entry
Table RBKP, with RSEG
Period Posting date 1 April 2026 to 30 September 2026
Company code Named codes; no other filter
Format Delimited text, field names in the first row
Owner Named person in the SAP team
Row count per SAP / in file Filled by the owner / checked on receipt
Control total Sum of gross invoice amount, agreed to purchases booked through purchasing for the period

The mistakes that waste a week

  • Asking for reports instead of tables. A report shows what its layout and filters allow. The table is complete and can be re-used for many tests. Use reports only to agree totals.
  • Missing line items. Headers arrive without items, and the request goes round again.
  • No document type. Without BLART in the journal extract, manual entries cannot be separated from system postings.
  • Extracts without totals. An extract with a filter left on will still load and still produce results. Agree row counts and control totals before running a single test.
  • An ECC table list sent to an S/4HANA team. Ask for ACDOCA and MATDOC directly.
  • Leaving out the change documents, then discovering that the master data only shows today's values.

Check the extract before testing

Check How
Row counts agree The count the SAP team states equals the count in the file
Debits equal credits Each document's lines add to zero, and so does the whole file
Line items agree to the trial balance Lines summed by account equal the trial balance movement for the period
Sub-ledgers agree to control accounts Vendor and customer open items total to the reconciliation accounts
Date range is full Earliest and latest posting dates are the first and last days requested
Archived periods identified The extract says from which date the tables are complete

A test run on an incomplete extract proves nothing about the population. And once the extracts are reliable, the same tables can be read on a schedule rather than once a year — which is how CORAA uses them, from SAP and from Tally, so that exceptions in payments, journals and access reach an owner as they arise.

SAP tables for audit FAQ

What are the main SAP tables for audit?

For the general ledger, BKPF and BSEG (or ACDOCA in S/4HANA). For purchases and payments, LFA1, LFB1, LFBK, EKKO, EKPO, EKBE, RBKP, RSEG, REGUH and REGUP. For sales, KNA1, KNB1, VBAK, VBAP, LIKP, LIPS, VBRK and VBRP. For assets, ANLA and ANLC. For inventory, MARA, MARD, MBEW and the material documents. For access and changes, USR02, AGR_USERS, AGR_1251, CDHDR and CDPOS.

Which SAP tables should internal audit request in 2026 on S/4HANA?

Request ACDOCA for all financial line items and MATDOC for material documents, in place of the separate ECC index, totals and material document tables. Master data, purchasing and sales tables keep their names. Ask the SAP team whether vendor bank details should come from the vendor table or the business partner table.

What is the difference between BSEG and ACDOCA?

BSEG is the accounting document line-item table used in ECC. ACDOCA is the Universal Journal in S/4HANA, holding every line item for finance, controlling and asset accounting in one table. In S/4HANA, ACDOCA is the complete source.

Which SAP table shows who changed a vendor bank account?

The change document tables. CDHDR gives the user, date, time and transaction; CDPOS gives the table, field, old value and new value. Request them for the vendor change object and the audit period.

In what format should SAP data be given to auditors?

One file per table with field names in the first row, unformatted dates and amounts, and the row count stated. Use delimited text for large line-item tables.

What is the Tally equivalent of an SAP data extract?

Reports exported to Excel: the Day Book for all vouchers, the Purchase, Sales, Payment and Receipt Registers, bill-wise outstandings, the Stock Summary, the ledger masters, and the users list and edit log where enabled.

Topics
SAP tables for auditSAP tables for internal auditSAP data for auditorsSAP audit data requestBKPF BSEG ACDOCA auditSAP ECC vs S/4HANA tables auditSAP vendor master tables audit
Share
← Back to all articles
Keep reading

More in internal audit.

Built for India · DPDPA compliant

Ready to automate your audit work.

See how Coraa reduces audit engagement time by 60%, from ledger scrutiny to working papers, all from one Tally import.

Run one complete audit free