CORAA
CORAA University · Free tool

SAP tables for audit data request builder 2026

The slowest part of an internal audit on SAP is asking for the data: the audit team asks for 'the vendor ledger', the SAP team asks 'which table?', and a fortnight goes by. Pick the process cycles and ECC or S/4HANA to get the tables to request, the key fields, what each is used for in testing, and the Tally equivalent for group entities not on SAP — then download the request list for FY 2026-27 with period, company code, format and owner columns.

What you are asking for
SAP release
Process cycles in scope
File format
Line-item tables often run past the row limit of a spreadsheet. For those, a delimited text file is the safer choice.
Process cycles
2
SAP ECC
Tables to request
19
Each with key fields and purpose
Tally equivalents
11
For group entities on Tally
Read this list as a starting point for a conversation with your SAP team, not as a specification. Table availability differs between ECC and S/4HANA; custom fields and custom tables carry much of the India-specific data (GST, TDS, approvals); and older periods may have been archived. Ask the team to confirm each table for your release and to tell you what is missing.
Procure-to-pay
TableWhat it holdsKey fieldsUsed in testing for
LFA1Vendor master — general dataLIFNR, NAME1, LAND1, ORT01, ERDAT, ERNAM, SPERR, LOEVMVendors created in the period and by whom; blocked or deleted vendors still transacted with; duplicate names.
LFB1Vendor master — company code dataLIFNR, BUKRS, AKONT, ZTERM, ZWELS, REPRFPayment terms and payment methods by vendor; whether the duplicate-invoice check is switched on.
LFBKVendor bank detailsLIFNR, BANKS, BANKL, BANKNBank accounts shared between vendors, or between a vendor and an employee.
EKKOPurchase order — headerEBELN, BUKRS, BSART, LIFNR, EKORG, BEDAT, ERNAM, AEDAT, FRGKEOrders raised after the invoice date; orders split to stay under an approval limit; release status.
EKPOPurchase order — itemsEBELN, EBELP, MATNR, TXZ01, MENGE, NETPR, NETWR, WERKS, LOEKZPrice of the same item across vendors and over time; deleted lines; order value by plant.
EKBEPurchase order history — receipts and invoices against each lineEBELN, EBELP, VGABE, BEWTP, BELNR, BUDAT, MENGE, DMBTRThree-way match: quantity and value received against invoiced, line by line; invoices booked before receipt.
RBKPVendor invoice (posted through purchasing) — headerBELNR, GJAHR, LIFNR, XBLNR, BLDAT, BUDAT, RMWWR, USNAM, STBLGDuplicate invoices; invoices dated before the order; reversed invoices; who posted.
RSEGVendor invoice — itemsBELNR, GJAHR, EBELN, EBELP, MENGE, WRBTRInvoice quantity and value against the order line.
BSIK / BSAKVendor open items / cleared itemsLIFNR, BELNR, XBLNR, BLDAT, WRBTR, SHKZG, UMSKZ, AUGBL, AUGDTVendor ageing; debit balances and open advances; which payment cleared which invoice.
REGUH / REGUPPayment run — payments and the invoices in eachREGUH: LAUFD, LAUFI, LIFNR, VBLNR, RWBTR. REGUP: LAUFD, LAUFI, BELNR, XBLNRPayments agreed to the bank statement; same amount paid twice; payments outside the run.
PAYRCheque registerCHECT, HBKID, VBLNR, LIFNR, RWBTRCheque sequence and gaps; cheques against payment documents. Only where cheques are issued from SAP.
Where PAN and GSTIN are stored on the vendor master depends on the India localisation and the release; ask for "vendor PAN and GSTIN" by description rather than by field name.
Tally equivalent
Ledgers under Sundry Creditors, exported from masters
Vendor list with PAN, GSTIN, address and bank details
Purchase Order Book and outstanding purchase orders
Orders, where order processing is used in Tally
Receipt Note Register
Goods receipts, where tracking numbers are used
Purchase Register with supplier invoice number and date
Vendor invoices
Payment Register and the bank books
Payments with instrument number and date
Bill-wise outstandings — Payables
Open bills, advances, debit balances and ageing
Record-to-report
TableWhat it holdsKey fieldsUsed in testing for
BKPFAccounting document — headerBUKRS, BELNR, GJAHR, BLART, BLDAT, BUDAT, CPUDT, USNAM, TCODE, XBLNR, BKTXT, STBLG, WAERSJournal testing: back-dated entries (entry date against posting date), entries by user, manual document types, reversals.
BSEGAccounting document — line itemsBUKRS, BELNR, GJAHR, BUZEI, KOART, SHKZG, HKONT, DMBTR, WRBTR, SGTXT, ZUONR, KOSTL, LIFNR, KUNNRThe other half of journal testing: accounts hit, amounts, narration, unusual account pairs.
FAGLFLEXAGeneral ledger line items (where the new general ledger is active)RLDNR, RBUKRS, RYEAR, DOCNR, RACCT, HSL, PRCTRLine items by ledger and profit centre.
GLT0 or FAGLFLEXTGeneral ledger totals — classic or new general ledgerRBUKRS / BUKRS, RYEAR, RACCT, HSLVT, HSL01 to HSL16Rebuild the trial balance and agree it to the line items received.
BSIS / BSASG/L account open items / cleared itemsBUKRS, HKONT, BELNR, BUDAT, DMBTR, SHKZG, AUGDTOld open items on clearing, suspense and control accounts.
SKA1 / SKB1 / SKATChart of accounts — account, company code settings, and namesSKA1: KTOPL, SAKNR, XBILK, KTOKS. SKB1: BUKRS, SAKNR, XSPEB. SKAT: SAKNR, TXT50Map accounts to the financial statements; accounts created in the period; blocked accounts posted to.
T001Company codesBUKRS, BUTXT, LAND1, WAERS, KTOPLConfirm which entities, currencies and charts of accounts the extract covers.
T001BPosting periods open, by account typeMKOAR, FRYE1, FRPE1, TOYE1, TOPE1Whether earlier periods are still open for posting, and for which account types.
In ECC, BSEG is a cluster table and cannot always be extracted in the ordinary way; many teams ask for the open and cleared item tables (BSIS/BSAS, BSIK/BSAK, BSID/BSAD) instead, which together give the same line items.
Tally equivalent
Day Book for the period, all voucher types
Every voucher with type, number, date, ledgers, amount and narration
Trial Balance, opening and closing
Control totals to agree the Day Book to
Journal Register
Manual journals
Ledger vouchers for selected ledgers
Detail for suspense, clearing, cash and related-party ledgers
List of Accounts — groups and ledgers
The chart of accounts and its grouping
Before any testing — prove the extract is complete
Selection screen kept
Ask for a screenshot of the selection used for each extract: client, company code, date range, and no other filters.
Row counts agree
The SAP team states the number of rows in each table for the selection; the file received has the same number.
Debits equal credits
In the line-item extract, the amounts for each document add to zero, and the whole file adds to zero.
Line items agree to the trial balance
Line items summed by account equal the movement in the trial balance for the same period.
Sub-ledgers agree to control accounts
Vendor and customer open items total to the reconciliation accounts in the general ledger.
Date range is full
The earliest and latest posting dates in the file are the first and last days of the period requested.
Document numbers run without unexplained gaps
Gaps within a number range are listed and explained (parked, deleted or not yet used).
Archived periods identified
If older data has been archived, the extract says from which date the tables are complete.
The fuller method for checking source reports before reliance is in the source data readiness guide.
Where this fits

This list covers system data only. An audit also needs documents that are not in any table: approvals, contracts, the delegation of authority, reconciliations, minutes. Those are in the internal audit data request list, which is written by process and works for any system. Use the two together: that one for what to ask the process owners, this one for what to ask the SAP team.

Ask for whole tables for the period rather than filtered reports. A report someone has filtered is a sample chosen by the person being audited; the table is the population. With the full line items in hand, tests such as the duplicate payment tests and journal-entry tests run on every transaction, and the same extract can be re-run every month.

Ask once, then every month

The real saving comes from the same extract, every month

A one-time data request supports one audit. The same tables read on a schedule mean management sees exceptions in vendor payments, journals and access as they arise, on every transaction, with an owner and a closure date — and the audit starts from data that is already there. CORAA works from extracts like these, from SAP and from Tally.

Planning what to test with the data? Score journal entries for risk or build the sampling plan for the areas where the full population is not available.

Which SAP tables to request for an audit in 2026

SAP keeps each kind of record in its own table, and an audit of a process needs a small, predictable set of them. For vendor payments that is the vendor master (LFA1, LFB1, LFBK), purchase orders (EKKO, EKPO), the purchase order history that links receipts and invoices to each order line (EKBE), vendor invoices (RBKP, RSEG) and payments (REGUH, REGUP). For sales it is the customer master (KNA1, KNB1), orders (VBAK, VBAP), deliveries (LIKP, LIPS) and billing documents (VBRK, VBRP). For the general ledger it is the accounting document header and line items (BKPF and BSEG), or the Universal Journal (ACDOCA) in S/4HANA.

This builder turns that into a request. You pick the process cycles in scope and whether the system is ECC or S/4HANA. For each cycle the page lists the tables, the fields that matter for testing, and what each table is used for, so that the SAP team understands why it is being asked for and can suggest a better source if one exists in your installation. The Excel download adds the columns that make it a working request: period, company code, format, owner, date received, row counts and whether control totals were agreed.

The difference between ECC and S/4HANA is mostly in finance and inventory. In S/4HANA every financial line item is in ACDOCA, and the older index and totals tables (BSIS, BSAS, BSIK, BSAK, BSID, BSAD, GLT0, FAGLFLEXT) exist only as compatibility views calculated from it. Material documents are in MATDOC in place of MKPF and MSEG. Vendors and customers are maintained as business partners, though the LFA1 and KNA1 tables are still filled. The page marks each of these when S/4HANA is selected.

Two cautions apply to every installation. First, custom fields and custom tables — names beginning with Z or Y — hold much of what an Indian company needs to test, such as GST and TDS details and approval data, and they differ everywhere. Second, older documents may have been archived and will not be in the live tables. Ask the SAP team to state both in writing when they deliver the extract.

Worked example — an illustrative procure-to-pay request for H1 of FY 2026-27

Illustrative only. A group's main operating company runs SAP ECC under one company code, and two smaller subsidiaries are on Tally. Internal audit is reviewing vendor payments for April to September 2026 and wants to test every invoice and payment rather than a sample.

Inputs
SAP releaseECC
Process cyclesProcure-to-pay; user access and change logs
Period and company code1 April 2026 to 30 September 2026; one company code
FormatDelimited text file, one per table
Output
Vendor masterLFA1, LFB1, LFBK — as at the extraction date
Orders, receipts and invoicesEKKO, EKPO, EKBE, RBKP, RSEG — by posting or document date in the period
Open and cleared vendor items, and paymentsBSIK / BSAK, REGUH / REGUP, PAYR
Changes to vendor mastersCDHDR and CDPOS for the vendor change object, for the period
Who could do whatUSR02, AGR_USERS, AGR_1251 — as at the extraction date
For the two Tally subsidiariesSundry Creditors masters, Purchase Register, Payment Register, bill-wise payables
With these files the team can match every invoice to its order and receipt through EKBE, run duplicate tests on RBKP, list every change to a vendor bank account from CDPOS and check whether a payment followed soon after, and see from the role tables who was able to both change a vendor and release a payment. None of that needs a sample.

Common mistakes

Asking for reports instead of tables
A standard report shows what its layout and filters allow. The same data taken from the table is complete and can be re-used for many tests. Ask for the table for the period, and use reports only to agree totals.
Counting amounts once per ledger in ACDOCA
ACDOCA holds a line for each ledger. Summing the whole table without choosing the leading ledger multiplies every amount. State the ledger in the request.
Assuming an ECC table list works on S/4HANA
Many ECC tables can still be read in S/4HANA, but as compatibility views that may be slow or restricted. Ask for ACDOCA and MATDOC directly and let the SAP team advise on the rest.
Leaving out the change documents
Master data as it stands today does not show that a vendor's bank account was changed for a week in June. CDHDR and CDPOS do. They are large, so request them by change object and date range.
Not agreeing the extract to the books
An extract with a filter left on, or a period missed, will still load and still produce results. Agree row counts and control totals to the trial balance before running a single test.
Requesting more personal data than the test needs
Employee tables hold personal data. Ask only for the fields the test needs, and agree how the files will be stored and when they will be deleted.

Frequently asked questions

What are the main SAP tables for audit?+
For the general ledger, BKPF and BSEG (or ACDOCA in S/4HANA). For purchases and payments, LFA1, LFB1, LFBK, EKKO, EKPO, EKBE, RBKP, RSEG, REGUH and REGUP. For sales, KNA1, KNB1, VBAK, VBAP, LIKP, LIPS, VBRK and VBRP. For assets, ANLA and ANLC. For inventory, MARA, MARD, MBEW and the material documents. For access and changes, USR02, AGR_USERS, AGR_1251, CDHDR and CDPOS.
Which SAP tables should internal audit request in 2026 on S/4HANA?+
On S/4HANA, request ACDOCA for all financial line items and MATDOC for material documents, in place of the separate ECC index, totals and material document tables. Master data, purchasing and sales tables keep their names. Vendors and customers are maintained as business partners, so ask the SAP team whether to extract bank details from the vendor table or the business partner table.
What is the difference between BSEG and ACDOCA?+
BSEG is the accounting document line-item table used in ECC. ACDOCA is the Universal Journal in S/4HANA, which holds every line item for finance, controlling and asset accounting in one table. In S/4HANA, BSEG is still written for finance documents but does not hold every line, so ACDOCA is the complete source.
Which SAP tables hold vendor master data?+
LFA1 holds general data such as name and address, LFB1 holds company-code data such as the reconciliation account and payment terms, and LFBK holds bank details. Changes to these are recorded in the change document tables CDHDR and CDPOS.
Which table shows who changed a vendor bank account in SAP?+
The change document tables: CDHDR gives the user, date, time and transaction, and CDPOS gives the table, field, old value and new value. Request them for the vendor change object and the audit period.
What is the Tally equivalent of an SAP data extract?+
In Tally the same information comes from reports exported to Excel: the Day Book for all vouchers, the Purchase, Sales, Payment and Receipt Registers, bill-wise outstandings for open items, the Stock Summary for inventory, the ledger masters for vendors and customers, and the users list and edit log where enabled.
In what format should SAP data be requested for audit?+
One file per table with field names in the first row, unformatted dates and amounts, and the row count stated. Use delimited text for large line-item tables, since they often exceed the row limit of a spreadsheet.
How do I know the SAP extract is complete?+
Agree the row count to what the SAP team reports, check that each document's debits equal its credits, agree line items by account to the trial balance movement, agree vendor and customer open items to the reconciliation accounts, and confirm the earliest and latest dates cover the period requested.

Authoritative sources

SAP Help Portal — product documentation for SAP ERP and SAP S/4HANA — Reference for standard table and field definitions and for the S/4HANA data model changes (Universal Journal, material documents, business partner). Confirm each table for your release.
TallyPrime Help — reports and export — Reference for the Day Book, registers, outstandings, stock reports, security control and the edit log.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Internal audit data request list (any system) →Source data readiness guide →Duplicate payment test kit →Journal entry risk scorer →ITGC audit workbook →Procure-to-pay audit workbook →
Share this tool
Last reviewed: 2026-10-01 · For informational purposes only — not professional advice.