TRK · 01
Learn to read SAP evidence and form a defensible professional judgment about it — before you ever get production system access. This is the entry point most controls, audit, and GRC careers actually start from.
Standalone judgment-first programme · pairs with Evidence Capture Training · no SAP login required to begin
Background
Almost nobody gets handed the keys to a live SAP system on their first day in controls or audit. What they do get is evidence: a role export, a segregation-of-duties report, an audit log extract, a Fiori catalog listing — and a request to say, in writing, whether it's a problem. That is the actual first-year job. The No-Access Track trains exactly this skill using real captured evidence rather than a simulated SAP screen, so the judgment you build transfers directly to a real review the first time someone hands you a file.
Who it's for
You'll feel at home here if
You're new to SAP entirely, moving into GRC or IT audit from a general accounting, IT, or compliance background, or preparing for a first-round interview and need to be able to speak fluently about access risk without having touched a live system yet.
You can start immediately even if
You've never logged into SAP, don't have a lab or sandbox, and don't yet know what SUIM, PFCG, or a segregation-of-duties conflict even are — the track builds that vocabulary from zero, chapter by chapter.
Scope covered
Each domain below is a chapter. You work through real evidence for that domain — exports, logs, screenshots, reports — and answer scored competency checks that mirror how a reviewer is actually questioned on the job.
Reading user, role, and authorization reports without configuring anything yourself.
Understanding how roles are actually built, so you can recognize a badly built one on sight.
Spotting conflicting access combinations from role and user export evidence.
Reviewing app assignments and catalog-to-role mapping for over-exposure.
Evaluating firefighter ID usage logs and after-the-fact review evidence.
Reviewing access-request workflow evidence for proper approval and business justification.
Evaluating periodic access recertification evidence for completeness and follow-through.
Reading GRC risk analysis reports and the mitigation documentation behind them.
Reviewing automated control monitoring output for exceptions that actually matter.
Reading change-document and table-log evidence for unauthorized or unusual changes.
Reviewing transport logs for change-control compliance across the landscape.
Applying the access / change / operations framework across every evidence type above.
Evaluating interface and connection security evidence between systems.
Reviewing system security parameter settings against policy expectations.
Reading audit log evidence for suspicious or unauthorized activity.
Course layout
Every chapter opens with a short explainer of what the domain is and why it matters to a controls review, then moves straight into real evidence.
Scored checkpoints distributed across the chapters. Each CVU presents a piece of evidence and asks you to form and defend a judgment about it — the same move a reviewer makes on a real engagement.
Selected CVUs include an evidence-pack spreadsheet you can open and work through directly, the way you'd receive a file from a client or engagement team.
Your console remembers exactly where you left off and what you've completed, so you can move at your own pace without losing your place.
What you'll walk away with
Finished judging evidence here? Evidence Capture Training teaches you to go produce the same 64 items yourself, inside SAP.
View Evidence Capture Training →No SAP access, no prior experience required — just sign in and begin with Chapter 1.