The SAP tables an internal audit normally asks for are BKPF and BSEG for accounting documents (ACDOCA in S/4HANA), LFA1, LFB1 and LFBK for vendors, EKKO, EKPO and EKBE for purchase orders, RBKP and RSEG for vendor invoices, REGUH and REGUP for payment runs, KNA1, VBAK, LIKP and VBRK for customers and sales, ANLA and ANLC for assets, MARA, MBEW and the material documents for inventory, and USR02, AGR_USERS, CDHDR and CDPOS for access and changes. Ask for each as a table extract for a stated company code and period, header and line tables together, with a row count and a control total you can agree to the trial balance.
The slowest part of an audit on SAP is usually the request itself: the audit team asks for "the vendor ledger", the SAP team asks "which table?", and a fortnight passes. This guide gives the request cycle by cycle, for the head of internal audit or finance controller who has to word it and the SAP team who has to run it.
Start here if you want the working file:
| Need | Use this |
|---|---|
| A request list in Excel for the cycles you pick, ECC or S/4HANA, with period, company code, format and owner columns | SAP Tables for Audit: Data Request Builder |
| A request list by process cycle for any accounting system | Internal Audit Data Request List |
| Checks to run before relying on any extract | Source data readiness guide |
A note before the tables: everything below uses standard, long-established SAP names. Table availability differs between ECC and S/4HANA, custom fields (names beginning with Z or Y) and archiving differ from one installation to the next, and your SAP team should confirm each table for the release in use.
How to ask
A request that gets answered in one pass states six things.
- Period. By posting date for documents. Master data and access tables as at the extraction date.
- Company code. Name them. No other filter — not by document type, not by user, not by plant.
- Production client only.
- Format. One file per table, field names in the first row, dates and amounts unformatted. Delimited text for large line-item tables, which often exceed the row limit of a spreadsheet.
- Header and line tables together. A header table without its items gives you dates and users but no amounts; items without the header give amounts but no document type or posting date.
- Change logs with the masters. The vendor master as it stands today does not show that a bank account was changed for a week in June. The change documents do.
And for every file: the selection screen used, the row count per SAP, and a total you can tie back.
Procure-to-pay
| Table | What it holds | Key fields |
|---|---|---|
| LFA1 | Vendor master — general data | LIFNR, NAME1, ERDAT, ERNAM, SPERR, LOEVM |
| LFB1 | Vendor master — company code data | LIFNR, BUKRS, AKONT, ZTERM, ZWELS, REPRF |
| LFBK | Vendor bank details | LIFNR, BANKS, BANKL, BANKN |
| EKKO / EKPO | Purchase order — header and items | EBELN, BSART, LIFNR, BEDAT, ERNAM, FRGKE / EBELN, EBELP, MATNR, MENGE, NETPR, NETWR |
| EKBE | Purchase order history — receipts and invoices against each line | EBELN, EBELP, VGABE, BELNR, BUDAT, MENGE, DMBTR |
| RBKP / RSEG | Vendor invoice posted through purchasing — header and items | BELNR, GJAHR, LIFNR, XBLNR, BLDAT, RMWWR, STBLG / BELNR, EBELN, EBELP, MENGE, WRBTR |
| BSIK / BSAK | Vendor open items / cleared items | LIFNR, BELNR, XBLNR, WRBTR, SHKZG, UMSKZ, AUGBL, AUGDT |
| REGUH / REGUP | Payment run — payments and the invoices in each | LAUFD, LAUFI, LIFNR, VBLNR, RWBTR / LAUFD, LAUFI, BELNR, XBLNR |
| PAYR | Cheque register, where cheques are issued from SAP | CHECT, HBKID, VBLNR, LIFNR, RWBTR |
These support the three-way match line by line, vendors created and paid in the same period, bank accounts shared between vendors, orders raised after the invoice date, and duplicate payment tests. Where PAN and GSTIN are stored depends on the India localisation and the release, so ask for "vendor PAN and GSTIN" by description rather than by field name.
Order-to-cash
| Table | What it holds | Key fields |
|---|---|---|
| KNA1 / KNB1 | Customer master — general and company code data | KUNNR, NAME1, ERDAT, ERNAM, SPERR / KUNNR, BUKRS, AKONT, ZTERM |
| VBAK / VBAP | Sales order — header and items | VBELN, ERDAT, AUART, KUNNR, NETWR / VBELN, POSNR, MATNR, KWMENG, NETWR, ABGRU |
| LIKP / LIPS | Delivery — header and items | VBELN, KUNNR, LFDAT, WADAT_IST / VBELN, POSNR, MATNR, LFIMG, VGBEL |
| VBRK / VBRP | Billing document — header and items | VBELN, FKART, FKDAT, KUNRG, NETWR, FKSTO / VBELN, POSNR, MATNR, FKIMG, NETWR, AUBEL |
| VBFA | Sales document flow | VBELV, POSNV, VBELN, POSNN, VBTYP_N |
| BSID / BSAD | Customer open items / cleared items | KUNNR, BELNR, XBLNR, BLDAT, ZFBDT, WRBTR, SHKZG, AUGBL, AUGDT |
These support cut-off testing (goods issued before the period end and billed after), deliveries not billed, cancelled invoices and credit notes, selling price by customer, and receivables ageing. Credit limits are held differently in ECC and S/4HANA; ask for "customer credit limits and exposure" as a report.
Record-to-report
| Table | What it holds | Key fields |
|---|---|---|
| BKPF | Accounting document — header | BUKRS, BELNR, GJAHR, BLART, BLDAT, BUDAT, CPUDT, USNAM, TCODE, XBLNR, STBLG |
| BSEG | Accounting document — line items | BUKRS, BELNR, GJAHR, BUZEI, KOART, SHKZG, HKONT, DMBTR, SGTXT, LIFNR, KUNNR |
| ACDOCA (S/4HANA) | Universal Journal — every line item, all ledgers | RLDNR, RBUKRS, GJAHR, BELNR, DOCLN, RACCT, HSL, BUDAT, BLART, USNAM |
| FAGLFLEXA (ECC, new general ledger) | General ledger line items by ledger | RLDNR, RBUKRS, RYEAR, DOCNR, RACCT, HSL, PRCTR |
| GLT0 or FAGLFLEXT | General ledger totals — classic or new general ledger | RBUKRS / BUKRS, RYEAR, RACCT, HSLVT, HSL01 to HSL16 |
| BSIS / BSAS | G/L account open items / cleared items | BUKRS, HKONT, BELNR, BUDAT, DMBTR, SHKZG, AUGDT |
| SKA1 / SKB1 / SKAT | Chart of accounts, company code settings, account names | KTOPL, SAKNR, XBILK / BUKRS, SAKNR, XSPEB / SAKNR, TXT50 |
| T001 | Company codes | BUKRS, BUTXT, WAERS, KTOPL |
| T001B | Posting periods open, by account type | MKOAR, FRYE1, FRPE1, TOYE1, TOPE1 |
This is the journal-testing population: back-dated entries (entry date against posting date), entries by user, manual document types, reversals, and old open items on suspense and clearing accounts. Document type (BLART) is what separates a manual journal from a system posting — never leave it out.
Fixed assets
| Table | What it holds | Key fields |
|---|---|---|
| ANLA | Asset master | BUKRS, ANLN1, ANLN2, ANLKL, TXT50, AKTIV, DEAKT |
| ANLZ | Time-dependent assignments | ANLN1, ANLN2, BDATU, ADATU, KOSTL, WERKS, STORT |
| ANLB | Depreciation terms by depreciation area | ANLN1, ANLN2, AFABE, AFASL, NDJAR, NDPER, AFABG |
| ANLC | Asset values by year and depreciation area | ANLN1, ANLN2, GJAHR, AFABE, KANSW, KNAFA, NAFAG |
| ANEP | Asset line items — additions, transfers, retirements | ANLN1, ANLN2, GJAHR, LNRAN, BWASL, ANBTR, BZDAT |
Ask for the capital work-in-progress ageing as a report; it is often tracked through internal orders or projects as well.
Inventory
| Table | What it holds | Key fields |
|---|---|---|
| MARA | Material master — general data | MATNR, MTART, MATKL, MEINS, ERSDA, LVORM |
| MARD | Stock by plant and storage location | MATNR, WERKS, LGORT, LABST, INSME, SPEME |
| MBEW | Material valuation | MATNR, BWKEY, BKLAS, VPRSV, VERPR, STPRS, LBKUM, SALK3 |
| MCHB | Batch stock | MATNR, WERKS, LGORT, CHARG, CLABST |
| MKPF / MSEG (ECC) | Material documents — header and items | MBLNR, MJAHR, BUDAT, USNAM / MBLNR, ZEILE, BWART, MATNR, WERKS, MENGE, DMBTR |
| MATDOC (S/4HANA) | Material documents — header and items in one table | MBLNR, MJAHR, ZEILE, BUDAT, BWART, MATNR, WERKS, MENGE, DMBTR |
| IKPF / ISEG | Physical inventory documents | IBLNR, GJAHR, WERKS, LGORT / IBLNR, MATNR, MENGE, BUCHM |
Payroll and HR
| Table | What it holds | Key fields |
|---|---|---|
| PA0000 | Personnel actions — joiners and leavers | PERNR, BEGDA, ENDDA, MASSN, STAT2 |
| PA0001 | Organisational assignment | PERNR, BEGDA, ENDDA, BUKRS, WERKS, KOSTL |
| PA0002 | Personal data | PERNR, NACHN, VORNA, GBDAT |
| PA0008 | Basic pay | PERNR, BEGDA, ENDDA, TRFGR, LGA01, BET01 |
| PA0009 | Bank details | PERNR, BEGDA, ENDDA, BANKL, BANKN |
| PA0014 / PA0015 | Recurring and one-off payments and deductions | PERNR, BEGDA, LGART, BETRG |
Payroll results are stored in clusters, not ordinary tables, and are normally requested as a wage-type report by employee and month. Many companies run payroll outside SAP; then the request goes to the payroll provider. Employee data is personal data — ask only for the fields the test needs, and agree how the files will be stored and when they will be deleted.
User access and change logs
| Table | What it holds | Key fields |
|---|---|---|
| USR02 | User logon data | BNAME, USTYP, GLTGV, GLTGB, TRDAT, UFLAG |
| AGR_USERS | Roles assigned to users | AGR_NAME, UNAME, FROM_DAT, TO_DAT |
| AGR_1251 | Authorisation values in each role | AGR_NAME, OBJECT, FIELD, LOW, HIGH |
| AGR_DEFINE | Role definitions | AGR_NAME, PARENT_AGR |
| UST04 | Profiles assigned to users | BNAME, PROFILE |
| CDHDR / CDPOS | Change documents — header and items | OBJECTCLAS, OBJECTID, CHANGENR, USERNAME, UDATE, TCODE / TABNAME, FNAME, CHNGIND, VALUE_OLD, VALUE_NEW |
| E070 / E071 | Transport requests and the objects in them | TRKORR, TRFUNCTION, TRSTATUS, AS4USER, AS4DATE / TRKORR, OBJECT, OBJ_NAME |
| DBTABLOG | Table change log, where logging is switched on | TABNAME, LOGDATE, USERNAME |
CDPOS is large; request it by change object and date range. The security audit log is kept only if it has been switched on, and is requested as a report for the period.
ECC versus S/4HANA: what changes in the request
| Area | SAP ECC | SAP S/4HANA |
|---|---|---|
| General ledger line items | BKPF with BSEG; FAGLFLEXA where the new general ledger is active | ACDOCA is the complete line-item source. BSEG is still written for finance postings but no longer holds every line |
| General ledger totals | GLT0 or FAGLFLEXT | Totals are calculated from ACDOCA; request the trial balance report and agree it to the sum of the extract |
| Open and cleared items | BSIS/BSAS, BSIK/BSAK, BSID/BSAD | Readable as compatibility views; the line items are in ACDOCA |
| Material documents | MKPF and MSEG | MATDOC; the older tables remain readable as compatibility views |
| Asset values and line items | ANLC, ANEP | Compatibility views; values are held in ACDOCA. Ask for the asset history sheet alongside |
| Vendors and customers | LFA1, KNA1 and related tables | Still filled, but maintained as business partners (BUT000), linked through CVI_VEND_LINK and CVI_CUST_LINK; bank details sit in BUT0BK |
Two practical points. In ECC, BSEG is a cluster table and cannot always be extracted in the ordinary way; many teams take the open and cleared item tables instead, which together give the same line items. In S/4HANA, ACDOCA holds a line for each ledger, so state the leading ledger in the request — otherwise every amount is counted more than once.
The Tally equivalent, for groups that run both
Many groups have the larger entities on SAP and the smaller ones on Tally. The audit needs the same information from both.
| Cycle | Ask the Tally entity for |
|---|---|
| Procure-to-pay | Ledgers under Sundry Creditors with PAN, GSTIN and bank details; Purchase Register with supplier invoice number and date; Receipt Note Register and Purchase Order Book where used; Payment Register; bill-wise outstandings for payables |
| Order-to-cash | Ledgers under Sundry Debtors; Sales Register and Credit Note Register; Delivery Note Register and Sales Order Book where used; Receipt Register; bill-wise outstandings for receivables |
| Record-to-report | Day Book for the period, all voucher types, with voucher number, ledgers, amount and narration; Trial Balance, opening and closing; Journal Register; List of Accounts |
| Fixed assets | Ledger vouchers under the Fixed Assets group; the asset register kept outside Tally; the depreciation working |
| Inventory | Stock Summary with the godown-wise view; Stock Journal Register; Physical Stock Register where used; stock ageing analysis |
| Payroll | Pay Sheet and Payroll Register where Tally payroll is used; otherwise the salary journal and bank advice |
| Access and changes | Users and security levels; the edit log of altered and deleted vouchers and masters, where enabled |
Report and column names depend on the Tally version and on which features are switched on.
Worked example: a filled request line
Illustrative only — one line from a procure-to-pay request for the first half of FY 2026-27.
| Field | Entry |
|---|---|
| Table | RBKP, with RSEG |
| Period | Posting date 1 April 2026 to 30 September 2026 |
| Company code | Named codes; no other filter |
| Format | Delimited text, field names in the first row |
| Owner | Named person in the SAP team |
| Row count per SAP / in file | Filled by the owner / checked on receipt |
| Control total | Sum of gross invoice amount, agreed to purchases booked through purchasing for the period |
The mistakes that waste a week
- Asking for reports instead of tables. A report shows what its layout and filters allow. The table is complete and can be re-used for many tests. Use reports only to agree totals.
- Missing line items. Headers arrive without items, and the request goes round again.
- No document type. Without BLART in the journal extract, manual entries cannot be separated from system postings.
- Extracts without totals. An extract with a filter left on will still load and still produce results. Agree row counts and control totals before running a single test.
- An ECC table list sent to an S/4HANA team. Ask for ACDOCA and MATDOC directly.
- Leaving out the change documents, then discovering that the master data only shows today's values.
Check the extract before testing
| Check | How |
|---|---|
| Row counts agree | The count the SAP team states equals the count in the file |
| Debits equal credits | Each document's lines add to zero, and so does the whole file |
| Line items agree to the trial balance | Lines summed by account equal the trial balance movement for the period |
| Sub-ledgers agree to control accounts | Vendor and customer open items total to the reconciliation accounts |
| Date range is full | Earliest and latest posting dates are the first and last days requested |
| Archived periods identified | The extract says from which date the tables are complete |
A test run on an incomplete extract proves nothing about the population. And once the extracts are reliable, the same tables can be read on a schedule rather than once a year — which is how CORAA uses them, from SAP and from Tally, so that exceptions in payments, journals and access reach an owner as they arise.
SAP tables for audit FAQ
What are the main SAP tables for audit?
For the general ledger, BKPF and BSEG (or ACDOCA in S/4HANA). For purchases and payments, LFA1, LFB1, LFBK, EKKO, EKPO, EKBE, RBKP, RSEG, REGUH and REGUP. For sales, KNA1, KNB1, VBAK, VBAP, LIKP, LIPS, VBRK and VBRP. For assets, ANLA and ANLC. For inventory, MARA, MARD, MBEW and the material documents. For access and changes, USR02, AGR_USERS, AGR_1251, CDHDR and CDPOS.
Which SAP tables should internal audit request in 2026 on S/4HANA?
Request ACDOCA for all financial line items and MATDOC for material documents, in place of the separate ECC index, totals and material document tables. Master data, purchasing and sales tables keep their names. Ask the SAP team whether vendor bank details should come from the vendor table or the business partner table.
What is the difference between BSEG and ACDOCA?
BSEG is the accounting document line-item table used in ECC. ACDOCA is the Universal Journal in S/4HANA, holding every line item for finance, controlling and asset accounting in one table. In S/4HANA, ACDOCA is the complete source.
Which SAP table shows who changed a vendor bank account?
The change document tables. CDHDR gives the user, date, time and transaction; CDPOS gives the table, field, old value and new value. Request them for the vendor change object and the audit period.
In what format should SAP data be given to auditors?
One file per table with field names in the first row, unformatted dates and amounts, and the row count stated. Use delimited text for large line-item tables.
What is the Tally equivalent of an SAP data extract?
Reports exported to Excel: the Day Book for all vouchers, the Purchase, Sales, Payment and Receipt Registers, bill-wise outstandings, the Stock Summary, the ledger masters, and the users list and edit log where enabled.